Concepts
The insurability layer
Cover is being withdrawn faster than teams can respond, and where affirmative cover exists every carrier writing it asks the same question: can you show what your agents can reach, and evidence that the controls hold? Most organisations cannot answer that in writing. Questionnaires describe — someone's recollection, once a year, a yes or a no. Evidence prices: exposure derived from the environment through read-only connectors, refreshed as permissions change, with the derivation shown. The difference matters most at claim, when application warranties get tested and cover is most often lost.
The Insurability Index
The Index is a composite of five dimensions weighted by how much each moves a price: exposure containment (30%, drives severity), authority definition (20%, drives frequency), attestation integrity (20%, drives warranty credibility), loss quantification (20%, drives pricing) and accountability (10%, drives legal standing). Six levels sit on that score — L0 Unmapped, L1 Inventoried, L2 Scoped, L3 Attested, L4 Quantified, L5 Underwritten — and each says what an underwriter will offer and what evidence it requires. The gap to the next level is the work order. Weights are set by underwriting judgement today and re-fit as loss experience accumulates; we say so rather than implying an actuarial precision that does not yet exist.
The grant is not the mandate
A grant is what the credential technically allows. A mandate is what the holder is allowed and expected to do. In practice the first is very much larger than the second, and the measurable difference — excess authority — is blast radius read from the other end: not what a compromise could reach, but what was handed over beyond what was needed. It is unaccepted by construction, because nobody wrote it down, so nobody could accept it; and unaccepted risk defaults to critical and escalates without anybody escalating it. A register row saying an agent has code-host access is not informative. One saying the grant covers forty-one repositories, the mandate covered one, with no acceptor, for six weeks, is a finding with a number in it. A mandate needs five fields — issuer, subject, scope, interval, revocation path — and a mandate with no clock is just a grant.
The signature mechanic: no deny button
Ask someone to accept a risk and they will do neither; treat acceptance as a choice and you hand them a third door, which is to do nothing. The risk is already on the books, so acceptance is not a decision to take it on — it is an acknowledgement that you already have. What remains are three doors with a name against each: accept it for a stated interval, fund the reduction, or fix it. There is no fourth door, and silence is not a decision anyone can underwrite. Every acceptance expires, and when it does the same decision lands back on the same desk with the risk still there and the evidence attached.
Never in the request path
Authorisation already happened: it was conferred the moment capability was, and what an agent can actually do is the union of every route to that capability. So the exposure can be derived by modelling what exists rather than by intercepting anything. Read-only digital twins model the primitives that matter, so coverage does not require a connector into every system, and telemetry is consumed to detect mapping error rather than to police traffic. A governance layer that can take your agents down is a new source of the risk it was bought to measure. The trade is stated plainly: we define the mandate and map the gap, and we do not enforce it — a declared mandate is instrumentation, not a control. Instrument before you enforce.
Accepted is not acceptable
Accepted is an act: somebody with standing says they carry this, attached to a named role, a date and an interval. Acceptable is a threshold: the level at which the business is content to stop funding remediation — a property of the business, not of the risk. They are orthogonal rather than sequential, which gives four real states: unowned and above the line is the dangerous one, owned and above the line is the normal state of a live programme, below the line but unowned cannot be relied upon, and owned and below the line is where remediation can stop. Missing acceptance is an ownership problem; a missing acceptable line is a governance problem. The EU AI Act requires residual risk to be judged acceptable without defining the word anywhere — the obligation is imposed, the standard is not supplied. Factual, not legal advice.
The foundation: SG/Vault
RiskMandate is built on SG/Vault: zero-knowledge, PKI-backed, provenance-carrying, with no database. The consequence for a buyer is that keys stay with the customer rather than the vendor, and a finished register can be handed to an auditor, a broker or a board as a read-only artefact rather than an export. Three live demonstrations run this way on the site today, each opened with a deliberately published read-only key.
Positioning
RiskMandate is not a carrier, a broker or an MGA, and does not sell or place cover; it measures insurability and produces the evidence underwriters price against. It is not a GRC platform either — those record risk, and this is the layer that makes the decision on a risk explicit, owned and expiring. It connects to identity providers, cloud IAM, agent posture and access governance rather than replacing them, and translates their output into exposure an underwriter can read. Two audiences, one score: enterprises walking into a renewal with an evidence pack, and brokers, carriers and MGAs pricing agentic risk from what is actually deployed.