Built for MGAs and program administrators, mutuals, risk pools, TPAs, and carriers standing up a new program

Agents build
your software.
Your filed rules
decide what ships.

The workflow you have to build and cannot staff, live in four to eight weeks, scoped and priced before it starts. A change that breaks a rule you filed never reaches a reviewer: it is refused before anyone is asked, and the refusal is a row with the rule on it.

A control you have only ever seen pass is a control you have not seen.

haltere · operation receipt · BLOCKEDfixture
request
CHG-2418 · workers’-comp rating change
the intent and the person with authority behind it: raise the loss-cost multiplier for hazard group C, inside the rating program’s scope. Nothing else.
one query: intent to production, unbroken
retrieved
program WC-MGA-2024 · filed rate FR-TX-2024-118 · band 1.38–1.61
exactly what the agent worked from, at the versions it saw: the program config, the filed rate on record with the state, and the band it has to stay inside
one query: what the AI was shown
drafted
claude-opus · prompt rating_change_v4 @a3f9c2 · proposed 1.71
the model that ran and the exact rendered prompt at its own SHA. What it proposed is on the record whether or not it ever shipped.
one query: the instruction, not a recollection of it
checked
✓ stay-in-scope  ✓ core-boundary  ✗ filed-rate-conformance
✗ filed-rate-conformance · rates.yml@r9 — 1.71 is outside the filed band 1.38–1.61.
the check ran before any effect, and it names the policy revision it ran against
effect
none. The change did not merge.
nothing reached the rating program: no version bump, no quote priced off it, nothing to roll back
the gate is a wall, not a warning comment
approval
never requested. A failed check does not ask for one.
no reviewer was paged and no approval queue entry was created. No person was ever placed in a position to wave it through.
one query: what was refused, and the rule that refused it
✗ blocked · recorded with the rule that matched

No human was asked. The rule ran first.

Two fixture changes, four days apart: CHG-2418 refused at the gate, CHG-2417 approved. Fields the spec marks proposed (the change number, the exhibit pack) appear as they will. Click any line.

Try it

Type your filed band.
Then try to break it.

Two numbers off one of your filings, and a value for the agent to propose.

the rule · rates.yml@r9 · fixture program WC-MGA-2024fixture

This is the fixture rule. Type your own band.

Fixture program, fixture rule, your numbers. The comparison runs in your browser and nothing you type leaves this page. In production a check of this shape runs in CI, before merge. There is no override in this panel: changing a rule you filed is its own change, with its own approval and its own row.

What compliance says first

“We’re not doing AI.
Compliance won’t let us.”

Then bring your compliance lead to the first call. The Model Audit Rule, the DOI exam, and every carrier audit ask who changed it, who reviewed it, and who approved it. Each of those is a column on the row, written while the work happened.

How it works

Three steps.
One receipt per change.

01 · The map

The software on the line, as it actually is.

Read from your code, never drawn by hand, and the build fails if it drifts.

02 · The gate

Agents build. Your people approve.

Checked against policy before it merges, then approved by a named person on your team. Bad changes don’t get reviewed. They get blocked.

03 · The receipt

Every change leaves one row.

Who asked, what ran, which checks passed, who approved, frozen to the exact code. Exam day becomes a query.

The three builds already on your list: submission intake · the Excel rater · bordereaux.

Walk the line in depth  ·  The architecture, for engineers

The scope of a first build

One workbook in.
This is what a build delivers.

A first build is one workflow, four to eight weeks, scoped and priced before anything starts. This is that scope, itemised, on a fixture program.

haltere · first build · scope of workfixture
what a build starts from · fixture
the workbook
Rating_WC_2024.xlsx · 9 tabs · 214 named ranges · 1,840 quotes in history
the filing
FR-TX-2024-118 · the filed band the rules have to stay inside
your side
one workflow owner · named reviewers who approve changes
what the build delivers · fixture counts
surface
7 endpoints · 1 nightly job · one door for every action
rules ported
23 rating rules, each one a check that runs before merge
tests
your own quote history is the test set; parity with the workbook is the acceptance condition
the map
derived from the code it ships with; the build fails if it drifts
dry run
what a change would touch, and how far, before it commits
the record
a receipt per change · retention set per class of information
evidence
the exhibits an examiner asks for, drawn from the receipts the line writes
fixture · a scope of work, not a delivery record
Fixture program, fixture workbook, fixture counts, drawn to the shape a scope of work takes. No workflow has been rebuilt for a paying customer. Every platform capability itemised here is listed on capability status with its basis and its date.

The receipt is what one change leaves behind. This is what one build is scoped to deliver. Both run on the same fixture program, WC-MGA-2024.

The difference

Wrap a workbook and you record
that it was opened. Not that the
multiplier left the filed band.

The trail stops at the boundary of whatever it calls. Haltere is what the systems are built out of, so the record covers the whole transaction you build on it, not one layer’s view of it.

What gets built is the software that was never a system: the rater in the workbook, the clearance nobody owns, the bordereau assembled by hand. Not your policy admin system, and not anything you rent. We switch nothing of yours off: the workbook keeps rating until you decide it stops. And not every workflow should be rebuilt — where the only statement of how one behaves is the thing itself, writing that down is the first part of the work. The argument, and the evidence against us

The receipt format is public, and so is a sample pack. Send both to the person who has to sign off.The receipt format · The sample evidence pack (PDF) · fixture data

Start with the workflow you
already have to build.

Thirty minutes with the engineers who build the line. Name the workflow and the examiner you answer to; we tell you what a governed build looks like, what it costs, and when it can start. Bring your compliance lead.

One workflow, four to eight weeks, scoped and priced before anything starts, live in your environment with the evidence pack. Afterward we run the line, or we train your operator to. Either way you own it and do not rent it, in open formats inside your boundary, and nothing you run trains us or anyone. Walk at renewal with everything.

Inquiries are answered within one business day, by someone who can answer them.