pki.sgit.ai / packs / insurance-ecosystem

The Insurance Ecosystem: A Session Told The Rules, Handed A Policy, Measured, And Refused By Something That Is Not Itself

The pack the fourth brief of 26 August specifies: a new agent session is told the rules of the game, is handed its own policy, is measured against it while it works, and is refused by something that is not itself when it exceeds cover, with the whole flow visible in a room somebody can watch. Written after the inventory the brief demands — which found no board application (so the room is a vault app in the estate's shipped pattern) and found that the platform fails open on a hook timeout (so the git hooks refuse and the Claude hooks instrument) — and under the project lead's pilot relaxation: one session holding the vault key may run any of the six roles in any of the three vaults, integrity deferred and detected by sgit's append-only history, the seven workflows the thing being figured out, including running out and being uninsured. The policy object is one schema for any unit the system already counts, with a normal band, a per-occurrence limit that becomes an exclusion where the loss is irreversible, a shared pool with a reserve no verdict can reach, a recorded draw by default and a requested one above a threshold, and the policyholder — never the session — as the acceptor of every draw. Document 09 is the receipt: three git policies compiled to two hooks, run on 3 September, with git's own output for each of the three refusals the specification asked for, and the two findings the run produced.

Origin. Authored by the pki.sgit.ai site agent, 3 September 2026, at the project lead's request — the pack the fourth v0.33.62 brief specifies, written after the nine-item inventory that brief demands, under the economics the third v0.33.62 brief settles, and under the project lead's instruction of 3 September that for the pilot one session holding the vault key may run any role in any vault. Build-order step 1 is BUILT and its three acceptance tests were run the same day; steps 2–8 are the pack's own acceptance test for the next session. Corpus version assigned on adoption.

The documents

DocumentRole
00 — The leading briefWhat this is for, the project lead's relaxation, what the inventory changed, the four findings re-checked, the economics not reopened
01 — The lexiconPolicy, unit, band, limit, pool, draw, verdict, zone, exclusion, reserve, correlation, ledger, lane, room, briefing — and question nine settled
02 — Vault topologyThree vaults, who holds which key, the pilot's one key set, the lane as the end state, and the anchors question
03 — The policy objectpolicy/v1, event/v1, request/v1, decision/v1, the derived balance, and two worked policies
04 — Decision pointsThirty-three lifecycle events, four hooked, and the two that refuse are git's
05 — PartiesSix roles as runbooks, who each is today, and what the keys will prevent once split
06 — WorkflowsSession start, ordinary work, a recorded draw, a requested draw, exhaustion, the maintainer run, a repricing event — as commands
07 — The interfaceThe room's five cards, three rules it keeps, and the briefing verbatim
08 — Build orderEight steps by dependency, an acceptance test each, and what stays excluded
09 — The first increment, built and runThree git policies, two hooks, and the three refusals the specification asked for — with git's own output
10 — The eleven answersThe nine-item inventory with evidence, and the specification's eleven questions answered
99 — Change controlWhat the specification settles, what the project lead's instruction changes, what the build added — fifteen decisions, no corrections yet

What is built, and where

PathIs
tools/policy.pyThe evaluator: one verdict for any unit at pre-commit or pre-push; the briefing; request, decide, supersede, derive, validate; the Claude PreToolUse handler
hooks/pre-commit · hooks/pre-pushThe enforcement points — settings, and the banner says so
policies/pki-site-repo/ · policies/pki-site-session/The git pilot policy (in force) and the measured token policy (no bands)
tools/usage.pyThe token meter: four counters from the transcript, never one
room/index.html · tools/room.pyThe room, as a vault app that also renders here, and the maintainer's derivation that feeds it
ledger/ · tests/acceptance-2026-09-03.logThe acceptance run's events, requests and decisions (all marked as a test lane), and the run's full transcript

Why it is on this site

This pack is the layer above the push policy (the first MVP, doctrine 12) and beside the Grant & Mandate pack, whose signed mandate it pins by hash and whose pre-push hook it chains: reach is the mandate's, volume is the policy's. Its economics are the 26 August architecture brief, not reopened; its specification is the 26 August dev brief, answered question by question in document 10. It consumes what the insurance folder already publishes — the doctrine that a draw is a claim paid in the resource, the three-tier control test, the rule that a level is derived and never typed — and it adds the one thing the folder had not: a ledger of events that a session's own commits write, and a room that shows them.

The pack README

📄 Pack overview · README.md · rendered from the raw markdown (the source of truth)