A risk read before it runs, kept
What kind of action, whether it can be undone, whether it reaches outside, whether it touches credentials. Read at the surface before it runs, written into the record, never guessed after the fact.
A normal audit log is testimony, and nobody can insure testimony. Carriers underwriting agentic AI cannot price a behavioral loss, the kind where the agent did the wrong thing while correctly authenticated, because no record exists to price it from. This one does.
What kind of action, whether it can be undone, whether it reaches outside, whether it touches credentials. Read at the surface before it runs, written into the record, never guessed after the fact.
The scoring engine is actuarial math, not a language model. It reports not enough evidence rather than manufacture a number, so every figure it gives carries the conditions it is entitled to exist under.
The score is computed where the evidence lives, on your infrastructure. The score can go to an underwriter. The record it came from never has to. Priced risk is what makes AI usage insurable.
Routine actions flow without ceremony. Consequential, credential-bearing, outward-facing, or hard-to-reverse actions meet warning, attestation, approval, or a hard stop.
Every action gets a risk score that declines to score when evidence cannot support it, and any action can meet a hard stop. Whether a step outside its permissions is refused, flagged, or only logged is a setting you control.