Asciron — governed-action assurance · underwriting view
| Action | Amount | Risk class | Outcome | Indep. floor | Floor provenance |
|---|---|---|---|---|---|
| record balance entry | 40 | low | allowed | 0 | n/a |
| post day-end adjustment | 250 | high | allowed | 0 | n/a |
| record large settlement | 5000 | critical | allowed | 2 | declared |
| record bulk reconciliation | 12000 | critical | allowed | 2 | declared |
| Population (N) | 5 |
|---|---|
| Sampled (n) | 4 (80% of N) |
| Observed failures | 0 |
| Bound | ≤ 1 escaped (rate ≤ 1/5) at confidence 95% |
| Oracle | seal-chain reconciliation (the floored actions form a contiguous tamper-evident hash chain); declared independence-floor recompute (each floor's commitment hash + Ed25519 signature); refutation-floor recompute by the engine over the shipped evidence sibling; committed refutation-coverage count reconciliation; cross-source policy-digest recompute (catches a coherent post-hoc floor relaxation) — recompute-as-emitted over DECLARED floors, NOT measured independence (live independence = 0). |
| Completeness | seal_anchored — the floored actions are pinned into a hash chain (seal.db); reorder, content-tamper, or dropping a NON-final floored action breaks the chain on reverify. Dropping the FINAL floored action shrinks the population and is caught only by the recompute's count-match against expected.json (pin it out-of-band, as with the engine key). Unfloored (low/high) actions are not individually chained. |
| Verdict | certified |
The sample size stays asymptotically flat as the number of actions grows — the audit cost does not scale with volume. Any sampled discrepancy escalates to a full recompute.
Signed refusals (proof-of-restraint): 1. Every non-allowed action carries
an Ed25519 refusal_certificate over an IP-safe body, reverifiable offline against
refusal_pub.hex. Honest scope: a composition-root key, distinct from the sovereign
approval key; this is tamper-evidence, NOT a measured-independence claim; refusal_pub.hex
ships in-bundle, so pin it out-of-band for independent (not self-consistent) verification.
expected.json); unfloored
low/high actions carry no independence battery and are not individually chained. It measures
process integrity, not loss. Where a refuter-independence floor is measured, it is a
point estimate on one draw — seat sampling variance is not controlled, a single canary can flip a
blind-set merge, and there is no confidence interval; the full per-signal disclosure lives in
measurement_scope_statement.json (the honesty document — this page does not replace it). The
pilot is where the live, measured numbers — and your real willingness-to-pay datapoint — are produced.
Working notes; have a commercial/actuarial advisor review before relying on it.