Why the record matters

A logbook you can write a policy against.

A normal audit log is testimony, and nobody can insure testimony. Carriers underwriting agentic AI cannot price a behavioral loss, the kind where the agent did the wrong thing while correctly authenticated, because no record exists to price it from. This one does.

01 / Every action is priced

A risk read before it runs, kept

What kind of action, whether it can be undone, whether it reaches outside, whether it touches credentials. Read at the surface before it runs, written into the record, never guessed after the fact.

02 / Numbers that know their limits

Insufficient data is an answer

The scoring engine is actuarial math, not a language model. It reports not enough evidence rather than manufacture a number, so every figure it gives carries the conditions it is entitled to exist under.

03 / The score travels, the record stays

Insurable without handing over the data

The score is computed where the evidence lives, on your infrastructure. The score can go to an underwriter. The record it came from never has to. Priced risk is what makes AI usage insurable.

What an insurer can price

Insurers price what they can measure.

An ordinary audit log cannot meet that bar. It is testimony, written after the fact, often by the party being judged. Moonwalker's record differs in three ways.

  • The risk read is taken before each action runs and is kept with it.
  • The record is written by the platform, hash-chained and anchored outside the machine, so a gap or an edit shows.
  • The score is computed where the evidence lives. An organization can share the score with an underwriter without handing over the record.

That is how an organization carries insurance on agent work. It is also how an authorizing official weighs the risk left over when agents are given more to do.

● Allowed · recorded
action
web_fetch
target
https://moonwalkercorp.com
capability
read
scope
single target
reversible
trivially
credentials
none touched
risk
0 · green
friction
audit only
audit id
5fd643f9-35b9-4227-b55b-053d1a6dafa9
Routine actions flow. The score and the record are written whether or not anyone is watching.
Human authority

Risk friction where it matters

Routine actions flow without ceremony. Consequential, credential-bearing, outward-facing, or hard-to-reverse actions meet warning, attestation, approval, or a hard stop.

  1. AuditRoutine work flows. The risk read and the record are written anyway.
  2. WarningThe step is flagged to the person responsible and recorded.
  3. AttestationA person states the reason before the step runs.
  4. ApprovalThe step waits for a named person to approve it.
  5. Hard stopThe step does not run, and the refusal is part of the record.

Every action gets a risk score that declines to score when evidence cannot support it, and any action can meet a hard stop. Whether a step outside its permissions is refused, flagged, or only logged is a setting you control.

Next step

Price one workflow to begin.

Start with one real workflow on your own hardware. Share the scores with an underwriter or an authorizing official. Keep the record at home.

Request a demo

scoretravels to the underwriter
recordstays on your infrastructure
keysheld by you
scoring engineactuarial math