Make your agents insurable.
Carriers are filing to exclude AI. RiskMandate measures what your agents can actually reach, evidences the controls that contain them, prices the exposure, and produces the record an underwriter will accept.
Carriers are filing to exclude AI. RiskMandate measures what your agents can actually reach, evidences the controls that contain them, prices the exposure, and produces the record an underwriter will accept.
Exclusions are attaching at renewal faster than teams can respond. Affirmative cover exists, but every carrier writing it asks the same question — and most teams cannot answer it in writing.
Standardised AI exclusion endorsements are now in circulation, and some exclusions on D&O and E&O lines are absolute rather than partial.
Whether AI is covered is decided policy by policy, jurisdiction by jurisdiction, at each renewal date — not once, centrally.
Can you show what your agents can reach, and evidence that the controls hold? Everything else follows from that answer.
Figures on this page describe a market in motion and are stated qualitatively on purpose; we cite specific filings and form numbers in the assessment itself, dated, rather than on a page that ages.
Underwriting agentic risk today runs on self-reported answers. The same three questions produce very different outcomes depending on where the answer comes from.
Every agent estate sits somewhere on this ladder. Your level determines what an underwriter will offer, and the gap to the next one is your work order. Select a level to see what it buys.
The Index is a composite of five dimensions, weighted by how much each one moves a price. It is derived from your environment through read-only connectors, never from a self-assessment. Weights are set by underwriting judgement today and re-fit as loss experience accumulates — we say so rather than implying an actuarial precision that does not yet exist.
How bad one agent can get. Reachable actions, systems touched, the value of the authority it holds, and whether the damage is reversible.
Drives severityWhether every agent has a written mandate: purpose, permitted actions, data scope, and the points where a human must intervene.
Drives frequencyWhether control state is evidenced continuously rather than asserted once a year, with logs and revocation tests that hold up under examination.
Drives warranty credibilityExpected loss per agent expressed as a range, not a point. A wide range is itself a finding — it means getting clarity is the next thing to fund.
Drives pricingWho owns each accepted risk, for how long, and at what retention. Acceptance without a named owner and an expiry date is not acceptance.
Drives legal standingMap every agent's blast radius, evidence the controls that contain it, and walk into your renewal with an evidence pack instead of a questionnaire.
Sits on top of your existing identity and posture tools. We read; we are never in the request path.
Price agentic risk from what is actually deployed in the insured's environment, and see where the same exposure repeats across your book.
Carrier-neutral by design. We score the risk; you set appetite and price.
A finding sitting in a backlog is not a decision, and an underwriter cannot price it. RiskMandate puts each risk through one of three doors, assigned to a named person for a stated interval. When the interval ends, the decision comes back.
A named executive holds this exposure for a set interval, with the amount written down.
The exposure justifies budget. The number is what makes the case.
Narrow the mandate or revoke the access, and the radius closes.
No. We are not a carrier, a broker or an MGA, and we do not sell or place cover. RiskMandate measures insurability and produces the evidence that underwriters price against. Your broker and carrier relationships stay exactly as they are.
Never. All connectors are read-only and out of band. A governance layer that can take your agents down is a new source of the risk it was bought to measure.
No, and it is not meant to. We connect to what you already run — identity providers, cloud IAM, agent posture and access-governance tools — and translate their output into exposure an underwriter can read. If you have no controls at all, we will tell you that before you buy anything.
It is a weighted composite of five dimensions, each derived from environment telemetry rather than a questionnaire. Every score decomposes to the evidence behind it, and the methodology is published. Weights are set by underwriting judgement today and re-fit as loss experience accumulates.
Connector setup is typically under a day. A first Index and gap list land inside two weeks, which is deliberately shorter than most renewal windows.
Metadata about agent scope and permissions, not the contents of what your agents process. Self-hosted and sovereign deployments are available where the data cannot leave your boundary.
A first assessment returns your Insurability Index, the gap list to the next level, and a renewal report written for an underwriter rather than a security team.