A remedy makes the promise commercial
On June 18, 2026, Atera announced an unusually legible promise for Robin, its autonomous IT agent. For high-volume enterprise customers admitted to the program, Robin will independently resolve at least 50% of Tier-1 and complex Tier-2 tickets within 90 days or Atera will waive all fees. The company names password resets, software deployments, and system troubleshooting among the work. A target, deadline, and advertised remedy are public; the contractual denominator and scope of waived fees still need definition.
The important signal is not Atera's separate claim that Robin can resolve 92% of technical issues over time. That is a vendor-reported product claim with no customer cohort or audit disclosed on the announcement page. The useful signal is that Atera is putting revenue at risk against a production result. Unlike access-only pricing, this promise at least specifies what happens when performance misses quota.
A guarantee also forces the work to become countable. Which tickets are Tier-1? What makes a Tier-2 ticket complex but eligible? Does autonomous mean no technician touched the case? Is a ticket resolved if the user reopens it tomorrow? Those questions are not objections to the product. They are the product learning how to wear a contract.
A fee guarantee is not loss coverage
The Atera promise is narrow in an instructive way. If the agent misses the 50% resolution threshold, the published remedy is waived fees. The page does not say Atera will cover the cost of a mistaken deployment, a locked account, downtime, lost data, or a security incident. It protects the buyer from paying for underperformance. It does not publicly promise to make the buyer whole for downstream loss.
That difference separates performance risk from liability risk. A workflow can miss its target without harming anything; it may simply need more human labor. It can also hit its aggregate target while one confidently closed ticket causes a very expensive afternoon. A fee waiver answers, 'Did the service deliver enough?' Insurance or indemnity answers, 'Who pays when the service causes covered damage?' Procurement needs both questions in separate columns.
This is not a complaint that the guarantee is weak. A bounded fee guarantee is a sensible first layer because it is measurable and survivable. The mistake would be reading it as a blanket warranty on autonomous action. Marketing enjoys a broad noun. Claims departments prefer a defined peril.
Managed services have somewhere to put responsibility
Patra's current site, accessed July 12, describes a different commercial wrapper for agent-led work. The company sells an agentic platform for insurance operations and managed services around policy checking, certificates, submissions, renewals, and endorsements. It says expert reviewers handle judgment, exceptions, critical decisions, and approvals, and that expert validation and errors-and-omissions accountability are built into the work.
The public page does not disclose coverage limits, exclusions, deductibles, or claims history, so it cannot establish how much risk Patra actually retains in any customer contract. It does show why vertical managed services may have an advantage over a general agent license. The provider already owns the process map, licensed labor, review layer, quality record, and professional-liability relationship. It has somewhere organizationally boring to put responsibility.
For a buyer, that wrapper can be more valuable than a higher benchmark score. A managed operator can pair capability with completion, expert sign-off, and contractual accountability. The agent is then not only labor inside the workflow. It is labor inside an accountable operating company.
Insurance is following the permissions
A March 2026 note from the International Underwriting Association shows why the insurance language is getting specific. The IUA said many AI risks were not expressly addressed in existing cyber, technology E&O, product-liability, or general-liability policies. It also noted that three ISO commercial-general-liability exclusion endorsements, effective January 1, 2026, explicitly exclude generative AI to varying degrees and were beginning to be adopted by some US carriers. That does not mean every ordinary policy excludes every agent loss. It means silence is no longer a comforting coverage strategy.
Mount, a Spring 2026 Y Combinator company, is selling directly into that ambiguity. Its current product page says it covers direct financial loss caused by verified AI-agent incidents, including unauthorized actions, erroneous actions, data or tool misuse, and manipulation events. The underwriting description begins with the deployed workflow: what the agent can do, what it can access, which controls exist, and where the financial downside sits.
Again, the public page is a product description, not evidence of a bound policy, paid claim, premium, limit, or loss ratio. Still, the shape matters. Mount describes its coverage around delegated authority and measurable workflow loss, not as a generic model trust badge. The risk follows the permission, which is less poetic than following the intelligence and substantially easier to put in a policy schedule.
The trace becomes a risk file
A research preprint submitted on June 15, 2026 offers a useful technical version of the same argument. The authors propose 'trace-economic underwriting': price risk at the customer-task-trace level by connecting an agent's actions to the assets exposed and the loss that could be claimed. Their basic requirements are a defined role, bounded permissions, and comparable traces. Generic AI risk is too foggy to price. A named agent doing a named job under a named authority limit is at least a candidate.
The reported effects are large and should remain in their proper container. On a synthetic portfolio, product-flat pricing mean absolute error was $17,700 versus $569 for trace pricing. In separate SWE-smith tests, an expert audit accepted 295 of 300 economic labels unchanged, and trace-conditioned control reduced modeled CVaR95 by 72% across 1,000 software-engineering agent traces. The economic labels were scenario-calibrated, not observed insured losses. This is a preprint, not an insurer's book of paid claims. It suggests a measurement direction. It does not settle the actuarial market before lunch.
The practical idea survives the caveat. A debug transcript is not yet a risk file. The business record must connect authorization, workflow and model version, data accessed, tools called, approvals requested, actions taken, completion evidence, customer impact, and reversal. Without the trace, a loss is hard to attribute. Without the exposure and customer consequence, the trace is merely an unusually detailed diary.
Write the failure contract before the headline
Start with one workflow whose failure can be detected and bounded. Define the eligible inputs and exclusions. Define acceptance in customer language, including reopen windows and whether any human touch disqualifies an autonomous result. Define the authority envelope: systems, records, spend, time, and actions the agent may use without approval. Then set a maximum exposure per action and per period, with irreversible work behind a smaller gate.
Next, define the evidence packet. Every claimed completion should carry a case identifier, policy and workflow version, relevant tool calls, approval events, before-and-after state, validation result, and delivery receipt. Define a remedy ladder before a customer tests it: automatic rework, fee reversal, service credit, indemnity review, or insurance claim. Name the owner and response time for each rung. 'Contact support' is not a claims process; it is a waiting room.
Finally, attach the promise to change control. A guarantee earned by workflow version 12 should not silently transfer to version 13 after a model swap, new connector, or expanded permission. Replay the covered cases, reset the evidence baseline, and decide whether the limit, reserve, or premium needs to move. Autonomous businesses will ship quickly. Their obligations should still know which release caused the bill.
The operator takeaway
Founders should accept bounded responsibility before advertising broad autonomy. Put one narrow fee pool at risk on one well-instrumented workflow. Estimate expected loss per accepted job as incident frequency multiplied by average severity, then carry a separate buffer for rare tail losses; price that reserve alongside remediation, review, and incident response in gross margin. If the company cannot define a valid failure, preserve evidence, and estimate the maximum loss, it is not ready to guarantee the work. It may still sell software. The distinction is healthy.
Buyers should request the contractual denominator and the last 90 days of evidence: eligible cases, true autonomous resolutions, reopened or falsely closed cases, human interventions, fees waived, incidents, remediation cost, and any claims made, denied, or paid. Ask for coverage limits and exclusions from the actual policy or certificate, not the homepage. Then find the gap between the fee guarantee, the vendor's indemnity, your own policies, and the loss the agent can create.
Operators should track claim frequency, severity, time to detect, time to reverse, evidence completeness, manual exception rate, and loss by workflow version. Record near misses where a control prevented harm; an empty paid-claims column can mean the system is safe or that nobody knows how to file. The mature autonomous business will not be the one that promises never to fail. It will be the one that can show what failed, cap the damage, and settle the obligation without convening a philosophy seminar.
Giving an agent a name does not assign accountability. The business becomes accountable when it agrees to own the result.
Autonomy without a remedy is a demo with unusually broad permissions.
- Atera introduces the world's first autonomous IT performance guaranteeAtera, accessed July 12, 2026
- The Agentic AI Platform Built for Insurance OperationsPatra, accessed July 12, 2026
- Insurance for deployed AI agentsMount, accessed July 12, 2026
- Mount: The AI Agent Insurance CarrierY Combinator, accessed July 12, 2026
- When Agent Automation Becomes Profitable: Quantifying and Insuring Autonomous AI Risk through Trace-Economic UnderwritingarXiv, accessed July 12, 2026
- AI Insurance: Standalone Solution or Policy Evolution?International Underwriting Association, accessed July 12, 2026