Skip to content

The module

What it is

The subrogation module is a rules-only subrogation thesis engine. A carrier sends structured claim data; the module returns a referral decision, the theory it rests on, the gates and defenses it evaluated, the money it can and cannot state, the deadlines it can compute, and an unabridged trace of how it got there. No language model sits on the path from carrier payload to thesis, and the harness asserts zero LLM client constructions per run .

The pipeline on the carrier path is the normalizer, JurisdictionResolverGKR, SensitiveIndicatorDetectorGKR Phase B (or detector_not_run), then SubrogationScreenerGKR. Liability and coverage are not run on this path and the trace records that they were not run .

The module was built and tested between 2026-09-24 and 2026-09-26 as a box test for a carrier POC, on synthetic claims, with both Auto and Property in scope and no restriction on jurisdiction. That test is the worked example behind most of what follows; it is not the subject. In October 2026 the POC line of business moved from Auto to Property. Property is adjudicated by the same engine on the same contract; its theories, gates, defenses and gaps are set out in Property Subrogation, and eight Property seeds are read in Property Worked Examples.

Input

Input is the carrier_structured profile of the generated manifest, external_idp_manifest, not a hand-authored schema. The same generator that produces the vendor manifest produces the carrier profile, so the field contract is one record with several projections .

Every fact arrives in the four-status envelope. A carrier may use only stated and not_stated; an omitted field is not_returned and resolves indeterminate. No other literal is accepted . The canonical intake schema now being generated per LOB keeps this shape: one envelope of value, status, source_ref and speaker everywhere, one party graph with a shared role enum and a stated identity status, damages as heads, facts not conclusions. Two projections remain, carrier_structured and idp.reducto, differing only in wrapping.

Before a run, the receipt mode of the harness returns what the payload stated, what it marked not stated and what it left out, scored against the subro analysis profile, so the carrier sees the completeness of its own input before any determination is made. The receipt is described in the harness chapter.

Output

The thesis has two layers. The surface has ten fields: referral with reason code and channel, primary theory with cited facts, other theories by status, gates and defenses, deadlines with status, preservation actions, recoverable_base and legally_recoverable, adverse exposure, verification items, and the completeness ledger. Beneath it sits the unabridged decision trace. The header carries the payload SHA-256, the spec versions and the ruleset hash, so a thesis can be tied to exactly the input and rules that produced it .

The referral enum is refer, investigate and no_referral, with a conditions[] list and a separate hold field. There are seven referral reason codes, including insured_at_fault and no_first_party_payment . Reason codes and statuses are closed enums; a non-enum value raises and nothing parses free text into one.

Money is never estimated. Each head is stated, computed from stated inputs, pending (rate and limit only), excluded, or indeterminate. Two recovery figures are shown separately: a base and a legally recoverable amount, the second pending until a stated fault percentage exists. A reserve is shown separately from recovery and carries no confidence percentage.

The corpus

The corpus holds eleven active theories at snapshot v1.9.0: five Auto (AUTO-001, 002, 003, 004, 006), six Property (PROP-001 to 006), and one workers' compensation theory (WC-SUBRO-THEORY-001, seeded and not yet on a tested path). AUTO-005 is approved, not active. Each theory is a record with a trigger, required facts, a channel and a caveat class where it applies .

LOB Theory Channel or note
AUTO Respondeat superior (v1.2.0) Narrative-required on trip purpose or assignment; route deviation moved to the frolic defense
AUTO Negligent entrustment Requires an owner other than the driver
AUTO Fleet negligence any_of five narrative fields
AUTO Product liability Lawsuit
AUTO At-fault third-party driver Intercompany arbitration when both carriers are members, else direct demand
AUTO Governmental vehicle (AUTO-005) Approved, not active, until governmental notice obligations are curated
PROPERTY Contractor negligence (PROP-SUBRO-THEORY-001) Demand letter; confirms on work performed described
PROPERTY Product liability (PROP-SUBRO-THEORY-002) Lawsuit; confirms on component failure described; disposition feeds spoliation
PROPERTY Utility negligence (PROP-SUBRO-THEORY-003) Demand letter; cause attribution required, plus a utility event
PROPERTY Tenant negligence (PROP-SUBRO-THEORY-004) Demand letter; tenant conduct required
PROPERTY Municipal negligence (PROP-SUBRO-THEORY-005) Government claim; cause attribution required, plus prior notice or condition duration
PROPERTY Neighbouring property (PROP-SUBRO-THEORY-006) Demand letter; roles adjacent_property_owner and neighbor; cause attribution required, plus source condition or prior notice

The requirement structure of each Property theory, and why four of the six need the cause tied to a party, is on the Property Subrogation page.

Defenses carry a caveat_class of routine_verification or material. On Auto, the independent contractor, comparative negligence and frolic defenses are routine and sovereign immunity is material. On Property all five defenses are material: waiver of subrogation (PROP-SUBRO-DEF-001, a full bar within the waiver's scope), the limitation period, sovereign immunity, act of God (a bar only when the natural event is the sole cause) and spoliation (PROP-SUBRO-DEF-005, a partial bar) . An earlier draft of this page called the waiver routine; the Property record is material. A not_stated on a defense trigger is a verified absence and the defense does not fire.

Phase 0 gates run before any theory: the comparative fault bar, no-fault evaluated per damage head, waiver, first-party payment, and candidate-target gating by party role. Unknown coverage never suppresses theory identification; it makes the payment gate indeterminate. On Property the gates differ in three places: no-fault does not apply; the comparative gate is not_applicable when no fault facts are stated, which the carrier format does not carry for Property; and the waiver gate reads two policy facts, the contract waiver and the lease waiver, each barring only the roles in its scope under SUBRO-WAIVER-SCOPE-v1 . The first-party payment gate reads the building coverage response. The arbitration channel is a carrier-membership fact seeded at tenant install, not a state fact.

Two governance rules protect the corpus. Bundles ship active or approved records only, never draft. A promotion from approved to active happens only under a ruling through the recorded path; a promotion made without one is reverted and the bundle rebuilt. AUTO-005 is the worked example: it was promoted to active without a ruling and reverted, because it stays at approved until governmental notice is curated.

Jurisdiction content

The AUTO subrogation section carries, per state, no_fault_state, threshold_type, pd_subrogation_permitted, bi_subrogation_regime (election-dependent for KY, NJ and PA, with election_default null everywhere), pd_recovery_regime (the Michigan mini-tort, 3,000 from 2020-07-02) and loss_transfer_rule as an enum with structured any_of triggers (New York: 6,500 lb unloaded or for-hire) . Statute of repose for construction and product is drafted and reviewed, with bar_type absolute or rebuttable presumption. Governmental notice is withdrawn pending a re-draft from statute text with deadline type, entity class and claim class. Property's comparative gate routes to the AUTO fault_system records, since state tort law is one record set.

Property reads less state content than Auto and needs more that is not yet curated. It uses the property-damage limitation period, the fault_system records, and, once wired, the construction and product statute of repose and the government notice section. Neither repose nor government notice is on the Property path today, so the brief states both as not assessed. The general P&C anti-subrogation rows exist but cannot be read by the tenant theory until a structured tenant_co_insured_rule is added. The Florida property negligence period is carried as four years; the 2023 amendment to Fla. Stat. § 95.11 made it two years for negligence accruing after 2023-03-24, and the record change is pending approval.

Provenance is printed on the brief. The twelve no-fault states (FL, HI, KS, KY, MA, MI, MN, ND, NJ, NY, PA, UT) were verified by the expert against live statute pages and load as Tier A, single_source; the other 39 are expert-drafted Tier B, llm_drafted, accepted for use now with the status shown on the provenance line. Both tiers load as draft through the recorded path and move to approved, never active, until the testing team verifies them in its 13-field discipline. Corrections made during that pass show what verification buys: North Dakota has no loss-transfer rule (repealed 2005), Michigan's mini-tort belongs to the owner so pd_subrogation_permitted is false, Minnesota's indemnity trigger is 5,500 lb curb weight, Hawaii reimburses only 50 percent from the insured's recovery.

What a carrier receives, and what never leaves

A carrier receives six things: the format guide, the receipt, the brief in HTML and PDF, the thesis JSON, the glossary and the scoring addendum . The intake schema is an interface, not intellectual property.

Everything else is internal: the domain guide written for the testing team, the seeds, the corpus, the jurisdiction registry, the evaluator, the sentence templates, the evaluation kit and every ruling. The domain guide in particular is never shared with a carrier's analysts, because they author the test claims.

The post-directive package PD-1

Ten carrier-practice items were identified beyond the box test. Four are built: the payment predicate, the party-unknown state, the two recovery figures and the lifecycle block. Deadline override is half built (status field only) .

Tier 1, before any brief reaches a carrier: the UM/UIM preservation item and its resolver section, and fault_pattern as a derived signal. Tier 2, before Phase 2 scoring: conditional evidence actions (applies_when), deadline override end to end, recall as a structured trigger from an imported NHTSA table, close-reason mapping and the outcome data request. The governmental notice re-draft and then AUTO-005 stay on the curation track.

Sell material

The positioning that the catalog and sell sheet carry, as decided:

  • Against suite AI, this is a different layer: determinations, not scores; an unbundled decision layer on the carrier's own knowledge, portable across claim systems, with no data gravity move. Concede workbench depth and cross-carrier benchmarks. The comparison to offer is one claim run side by side.
  • The sell sheet gains a "how it runs in your environment" page, the sentence that models read while rules decide, an "honest about gaps" pillar, structured-data intake as a third door, no confidence percentage on recovery, reserve and recovery shown separately, and 51 jurisdictions.

Open items

  • Governmental notice re-draft, then AUTO-005 activation; sovereign immunity coverage pendings for AUTO and PROPERTY.
  • HI, MA and UT AUTO subrogation records held in draft pending sourcing; effective_from for remaining states.
  • Posture enum and channel-rule evaluator logged as debt; carrier membership records.
  • Tenant re-export (BT-R3) before anything reaches a carrier; readiness run and blind-authoring test.
  • Source citation from the carrier is deferred past the POC and will be added without changing the carrier_structured schema.
  • Property: SL-FIX-07P (waiver-scope crash, act-of-God defense aligned with the sole-cause rule, insured-target condition, lost-evidence reasoning, fault-rule label from the record, Property brief wording); statute of repose wiring; government notice; implied co-insured tenant; a landlord theory; two candidate targets beyond the v1.0 limit; the Florida limitation record.