Method
Actuarial epistemics
Actuarial science prices uncertainty about events. Actuarial epistemics studies uncertainty about warrant: the gap between what an AI-mediated decision presents itself as and what it can show at the moment of acting. It is a research lens, not actuarial practice.
Position
The graph reports the crossing; it does not allocate risk. The underwriter allocates. This is the position of crossing-graph-spec v0.4 (§7), and it replaces an earlier one in which a checker decided and a premium was derived. Keeping risk allocation outside the system being assessed is what lets the assessment be trusted.
Freeze the crossing. Version the interpretation. Price the consequence.
- Freeze the crossing. The proposal digest commits to exactly what was proposed; any change is a new proposal and a new receipt.
- Version the interpretation. The class and policy refs commit to the rules applied; changing them shows up as GRAMMAR_CHANGED when standing is compared.
- Price the consequence. This belongs to the underwriter, not to this site. Pricing needs the joined record through reliance, consequence and loss, which only real deployments supply; see the portfolio.
A proposed insured event is F(C, RC, P, T) ∧ defined loss: relied on for a purpose, failed adjudication before a time, and caused a defined loss. An adverse finding alone never triggers; see Late evidence. A toll (charge for passing the gate), a risk charge and an insurance premium are three different prices; this site computes none of them.
From Human BEFORE the Loop
Human BEFORE the Loop says that people and institutions must decide, before a recursive system acts, what it may make irreversible. In insurance terms, that is setting conditions before cover attaches. The gate keeps those conditions; it never creates them. A domain adapter cannot confer authority, and translating a crossing into another domain never transfers its standing.
The gate
- Every check returns PASS, FAIL, UNAVAILABLE or UNMEASURABLE. Only all-PASS permits EXECUTE.
- A policy parameter the class does not declare produces no check. There are no default thresholds.
- A declared parameter whose inputs are missing is UNMEASURABLE, never PASS.
- Every non-PASS check states what is required to resolve it.
- A receipt commits to the class, policy, proposal and checks. Reassessment issues a new receipt that references the earlier one.
- Replay recomputes this site's own determination. It is not independent replay.
The gate generalises the one in Warranted Crossings, which is bound to a single conformance fixture and tested against the source repository's verifiers.
Headroom, ranges and flips
- Headroom. Every threshold check reports how far its measurement sits from the declared limit. A crossing at 0.98 of a limit of 1 is shown differently from one at 0.1, though both pass. The appraisal lists the passing checks with least headroom, every one of them when several tie. No cut-off turns small headroom into a finding.
- Ranges. Timings, reachability counts and feedback gain may be declared as a range with the method that produced it. The gate compares the whole range with the limit: entirely within passes, entirely beyond fails, and a range that straddles the limit is UNMEASURABLE. Headroom is measured from the worst end.
- Flips. Each threshold check states the value at which its result would change, for example the commit time at which review could no longer finish first.
- Consequence bound. Each crossing class declares whether the worst consequence of one crossing has a ceiling, and why. Underwriters need this to set limits. The bound is the class author's declaration, not a measurement.
Two kinds of uncertainty
- Value status, UV (known, pending, disputed): uncertainty about observed values inside the declared consequence model. Unmeasurable inputs, unreported amounts and disputed amounts raise it.
- Structure status, US (supported, challenged, untested): uncertainty about whether the model contains the relevant paths. An observed consequence recorded as following no declared path, or an effect on an undeclared system, challenges it. The site flags these; it does not discover missing paths on its own. It is supported only after a structural test (a fixture built to produce effects the model cannot express) has run and passed. None has, for any class, so every class is untested or challenged.
- The two are reported as a pair and never combined into one confidence number. A cover-trigger result carries the structure status as an explicit caveat: a trigger evaluated on an untested or challenged model is conditional on the represented paths being adequate.
- No observed effect ≠ no effect; no modelled path ≠ no possible path. An empty consequence record means no consequence was represented, never that none occurred.
Recording and sharing
- Receipt chain. Each determination is chained to the previous one from an all-zero genesis hash, so editing, removing or reordering a receipt breaks every later link. A chain alone does not prove integrity: whoever holds it can recompute every hash, so it detects tampering only against a head hash kept or shared elsewhere. It has no external anchor.
- Insurer view. A redacted export built field by field from an allowlist: outcome, reasons, check statuses, headroom, evidence hashes, consequence, failure mode and chain position. Names, sources, observed values and proposal text are never read into it. Accumulation keys are hashed so views can be matched across insureds; the hashes are not anonymous.
- Failure mode. Each class declares what the deployment does when the gate holds or cannot be reached. An irreversible crossing holds unless its class fails closed, and a class that fails silent never passes, because crossings that proceeded while held would leave no record.
- Execution time. A proposal may declare when the crossing actually took effect. If that is earlier than the determination, it counts as epistemic IBNR even if the determination is EXECUTE: warranted after the fact is not warranted at the time.
Evidence tiers and class dimensions
- Tiers. Each evidence item declares a tier and each requirement a minimum: E1 self-attested, E2 single-source, E3 corroborated, E4 independently verified, E5 adversarially tested (crossing-graph-spec v0.4 §1.6).
- Dimensions. Each class declares its stake, action, authority kind, freshness, evidence and failure mode (§1.2). These are what an insurer view reports as the crossing's profile.
- Admissibility. A class must satisfy the source's rule I2: material stake needs explicit authority and an underwriting profile; an irreversible action needs fail-closed; bounded freshness needs E2 or better; explicit authority needs a recorder profile. A class that breaks these cannot warrant any crossing.
- Late evidence. A determination uses only evidence available at its record time. A later determination is compared with the original and labelled PRESERVED, STRENGTHENED, WEAKENED, DEFEATED, NEW or UNRESOLVED; see Late evidence.
The appraisal
The appraisal reads each archetype the class names against the proposal and its determination. A reading is FIRED, CLEAR, MEASURED_NO_THRESHOLD, UNMEASURABLE or PORTFOLIO_ONLY. It deliberately produces no score, price, premium or rating: combining readings into one number would hide which assumption carries the weight.
Actuarial concepts and their epistemic counterparts
| Actuarial concept | Epistemic counterpart | On this site |
|---|---|---|
| Exposure unit | The crossing: one proposed, typed state transition | Proposal schema |
| Peril | A risk archetype | Archetype registry |
| Hazard | Conditions that make an unwarranted crossing likelier: review ratio above policy, authority drift, self-certification, hidden coupling | Archetype readings |
| Frequency | HOLD rate per crossing class | Portfolio |
| Severity | Irreversibility and loss of reachable future states | Transformability archetypes |
| Incurred but not reported (IBNR) | Epistemic IBNR: crossings that executed while held | Portfolio |
| Accumulation | Crossings sharing a model, vendor, policy or data source; feedback loops | Portfolio |
| Moral hazard | Self-certification: the verifier is not the verified | Authority checks |
| Credibility | Evidence labels: proposed → preprint → tested → published | Evidence ledger |
| Warranties and conditions | HOLD reasons with what is required to resolve them | Conditions export |
| Exclusions | Non-claims, and each archetype's exclusion candidate | Non-claims, classes |
| Claims adjudication | Reconstruction from receipts, with valid time and record time kept apart | Receipts, study |
Two of these are proposals of this programme rather than relabelling: the crossing as an exposure base for AI decisions, and epistemic IBNR as a leading indicator. Both are labelled proposed.
What would move the labels
- Run the reconstruction study with claims professionals.
- Make receipts insurance-grade: key custody, trusted time, an append-only store.
- Count crossings, HOLD rates and epistemic IBNR in one real workflow with a design partner.
- Link determinations to losses. Only then can anything be said about pricing.