The Insurance Ecosystem: A Session Told The Rules, Handed A Policy, Measured, And Refused By Something That Is Not Itself
The pack the fourth brief of 26 August specifies: a new agent session is told the rules of the game, is handed its own policy, is measured against it while it works, and is refused by something that is not itself when it exceeds cover, with the whole flow visible in a room somebody can watch. Written after the inventory the brief demands — which found no board application (so the room is a vault app in the estate's shipped pattern) and found that the platform fails open on a hook timeout (so the git hooks refuse and the Claude hooks instrument) — and under the project lead's pilot relaxation: one session holding the vault key may run any of the six roles in any of the three vaults, integrity deferred and detected by sgit's append-only history, the seven workflows the thing being figured out, including running out and being uninsured. The policy object is one schema for any unit the system already counts, with a normal band, a per-occurrence limit that becomes an exclusion where the loss is irreversible, a shared pool with a reserve no verdict can reach, a recorded draw by default and a requested one above a threshold, and the policyholder — never the session — as the acceptor of every draw. Document 09 is the receipt: three git policies compiled to two hooks, run on 3 September, with git's own output for each of the three refusals the specification asked for, and the two findings the run produced.
The documents
| Document | Role |
|---|---|
| 00 — The leading brief | What this is for, the project lead's relaxation, what the inventory changed, the four findings re-checked, the economics not reopened |
| 01 — The lexicon | Policy, unit, band, limit, pool, draw, verdict, zone, exclusion, reserve, correlation, ledger, lane, room, briefing — and question nine settled |
| 02 — Vault topology | Three vaults, who holds which key, the pilot's one key set, the lane as the end state, and the anchors question |
| 03 — The policy object | policy/v1, event/v1, request/v1, decision/v1, the derived balance, and two worked policies |
| 04 — Decision points | Thirty-three lifecycle events, four hooked, and the two that refuse are git's |
| 05 — Parties | Six roles as runbooks, who each is today, and what the keys will prevent once split |
| 06 — Workflows | Session start, ordinary work, a recorded draw, a requested draw, exhaustion, the maintainer run, a repricing event — as commands |
| 07 — The interface | The room's five cards, three rules it keeps, and the briefing verbatim |
| 08 — Build order | Eight steps by dependency, an acceptance test each, and what stays excluded |
| 09 — The first increment, built and run | Three git policies, two hooks, and the three refusals the specification asked for — with git's own output |
| 10 — The eleven answers | The nine-item inventory with evidence, and the specification's eleven questions answered |
| 99 — Change control | What the specification settles, what the project lead's instruction changes, what the build added — fifteen decisions, no corrections yet |
What is built, and where
| Path | Is |
|---|---|
tools/policy.py | The evaluator: one verdict for any unit at pre-commit or pre-push; the briefing; request, decide, supersede, derive, validate; the Claude PreToolUse handler |
hooks/pre-commit · hooks/pre-push | The enforcement points — settings, and the banner says so |
policies/pki-site-repo/ · policies/pki-site-session/ | The git pilot policy (in force) and the measured token policy (no bands) |
tools/usage.py | The token meter: four counters from the transcript, never one |
room/index.html · tools/room.py | The room, as a vault app that also renders here, and the maintainer's derivation that feeds it |
ledger/ · tests/acceptance-2026-09-03.log | The acceptance run's events, requests and decisions (all marked as a test lane), and the run's full transcript |
Why it is on this site
This pack is the layer above the push policy (the first MVP, doctrine 12) and beside the Grant & Mandate pack, whose signed mandate it pins by hash and whose pre-push hook it chains: reach is the mandate's, volume is the policy's. Its economics are the 26 August architecture brief, not reopened; its specification is the 26 August dev brief, answered question by question in document 10. It consumes what the insurance folder already publishes — the doctrine that a draw is a claim paid in the resource, the three-tier control test, the rule that a level is derived and never typed — and it adds the one thing the folder had not: a ledger of events that a session's own commits write, and a room that shows them.