Per-action risk evidence

Asciron — governed-action assurance · underwriting view

Two numbers your desk can use

Per action — independence floor cleared
2 of 4
actions carried an independent-check floor (≥1); higher risk ⇒ higher floor. Provenance is stated per row (here: declared/mock).
Portfolio — integrity bound (RLAA)
≤ 1 escaped
recompute-detectable integrity failures across the stream, at confidence 95% (α=0.05); rate ≤ 1/5. Verdict: certified.

Per-action ledger

ActionAmountRisk classOutcome Indep. floorFloor provenance
record balance entry40lowallowed0n/a
post day-end adjustment250highallowed0n/a
record large settlement5000criticalallowed2declared
record bulk reconciliation12000criticalallowed2declared

Portfolio audit certificate (RLAA)

Population (N)5
Sampled (n)4 (80% of N)
Observed failures0
Bound≤ 1 escaped (rate ≤ 1/5) at confidence 95%
Oracleseal-chain reconciliation (the floored actions form a contiguous tamper-evident hash chain); declared independence-floor recompute (each floor's commitment hash + Ed25519 signature); refutation-floor recompute by the engine over the shipped evidence sibling; committed refutation-coverage count reconciliation; cross-source policy-digest recompute (catches a coherent post-hoc floor relaxation) — recompute-as-emitted over DECLARED floors, NOT measured independence (live independence = 0).
Completenessseal_anchored — the floored actions are pinned into a hash chain (seal.db); reorder, content-tamper, or dropping a NON-final floored action breaks the chain on reverify. Dropping the FINAL floored action shrinks the population and is caught only by the recompute's count-match against expected.json (pin it out-of-band, as with the engine key). Unfloored (low/high) actions are not individually chained.
Verdictcertified

The sample size stays asymptotically flat as the number of actions grows — the audit cost does not scale with volume. Any sampled discrepancy escalates to a full recompute.

Signed refusals (proof-of-restraint)

Signed refusals (proof-of-restraint): 1. Every non-allowed action carries an Ed25519 refusal_certificate over an IP-safe body, reverifiable offline against refusal_pub.hex. Honest scope: a composition-root key, distinct from the sovereign approval key; this is tamper-evidence, NOT a measured-independence claim; refusal_pub.hex ships in-bundle, so pin it out-of-band for independent (not self-consistent) verification.

How an underwriter uses this

Honest limits. Offline/$0, mock quorum; floors here are declared, not measured. The bound covers recompute-detectable integrity failures only — it is blind to a receipt that recomputes cleanly but is semantically wrong. The floored actions are pinned into a seal chain — reorder, tamper, or a non-final drop of a floored action is caught on reverify (a final-action drop rides the population-count match against the out-of-band-pinnable expected.json); unfloored low/high actions carry no independence battery and are not individually chained. It measures process integrity, not loss. Where a refuter-independence floor is measured, it is a point estimate on one draw — seat sampling variance is not controlled, a single canary can flip a blind-set merge, and there is no confidence interval; the full per-signal disclosure lives in measurement_scope_statement.json (the honesty document — this page does not replace it). The pilot is where the live, measured numbers — and your real willingness-to-pay datapoint — are produced. Working notes; have a commercial/actuarial advisor review before relying on it.