Insurance Carriers

Govern the access behind policies, claims, payments, and customer data.

Know who can quote or change a policy, approve or settle a claim, issue a refund, administer producer access, reach nonpublic information, or use privileged credentials across the insurance application estate.

Start with access certification across core insurance systems. Then extend into access requests, lifecycle, temporary claims staffing, service accounts, third-party access, identity monitoring, and broader risk governance.
Insurance Access Governance
High-impact access requiring attention
Carrier view
Claims · Settlement Authority
Senior Adjuster · elevated payment authority
Review
Policy · Underwriting Override
Commercial Underwriter · quote/bind authority
Sensitive
Billing · Refund Administration
Billing Specialist · customer payment access
Certify
Producer Portal · Agency Admin
External producer administrator · delegated access
Third party
Govern the business authority behind the entitlement—not just the technical role name.
Why insurance is different

An insurance entitlement can represent real business authority.

The access-risk question is not simply “does this employee have the application?” It is what that person can do inside the policy, claims, billing, underwriting, producer, financial, and customer-data workflows.

Policy authority

Who can quote, bind, issue, endorse, cancel, reinstate, or override policy and underwriting decisions?

Claims authority

Who can create or change reserves, approve settlements, authorize payments, or modify claim outcomes?

Billing authority

Who can change payment information, issue refunds, adjust balances, waive fees, or alter collection activity?

Producer / agency authority

Who can administer agency users, producer access, appointments, commissions, or delegated portal rights?

Nonpublic information

Who can access policyholder, claimant, beneficiary, health, financial, or other protected customer information?

Privileged technology access

Who can administer core insurance applications, databases, integrations, cloud environments, or service accounts?

The insurance customer journey

Start with certification. Build toward continuous control of insurance access.

A carrier can begin with the access-review obligation and then use the cleaned identity and entitlement data to improve requests, lifecycle, temporary access, third-party governance, and identity-risk monitoring.

01 · Discover

Map the insurance estate

Policy, claims, billing, underwriting, producer, finance, data, directory, and HR systems.

02 · Certify

Review business authority

Managers and system owners decide whether sensitive access is still appropriate.

03 · Remediate

Close revoke decisions

Track tickets, automation, exceptions, and proof that access was removed.

04 · Standardize

Build insurance access patterns

Use real access to define templates for underwriters, adjusters, billing, and other roles.

05 · Automate

Control access changes

Requests, approvals, JML, CAT staffing, and temporary access follow defined workflows.

06 · Monitor

Watch identity risk

See dormant entitlements, privileged access, service accounts, APIs, and AI identities.

07 · Prove

Support cyber & risk governance

Retain evidence for access control, third parties, remediation, and risk oversight.

Stage 01 · Discover

Bring the insurance systems that drive business authority into scope.

Core insurance access is often spread across applications, directories, reports, databases, and external portals. The first step is creating one governed identity-and-access view.

Customer outcomeA review population that includes the systems and accounts that actually influence policy, claims, payments, and customer data.
Policy AdministrationPolicyCenter, Duck Creek Policy, and other PAS environments.
ClaimsClaimCenter, Duck Creek Claims, specialist claims systems, and adjuster tooling.
Billing & PaymentsBillingCenter, Duck Creek Billing, payment, refund, and receivables workflows.
Underwriting & RatingRisk selection, underwriting workbench, quote, bind, rating, and override access.
Producer / Agent SystemsAgency portals, producer administration, delegated users, commissions, and partner access.
Finance & ReinsuranceGeneral ledger, treasury, statutory reporting, reinsurance, and financial-control systems.
Data & AnalyticsData warehouses, actuarial platforms, reporting environments, and customer-data stores.
Identity & WorkforceAD/Entra, Okta, HR, contractor records, SaaS, databases, files, and service accounts.

Do not wait for a perfect connector strategy.

For each system, use the supported onboarding method that fits—standard connector, directory relationship, database extraction, API, secure file/SFTP, or other controlled ingestion method. The objective is to get the access into scope without pretending every insurance application integrates the same way.

Stage 02 · Certify

Review the authority behind the role.

A role called “Claims Supervisor” or “Policy Admin” is not enough context. Reviewers need to understand the actual authority, customer data, and business process attached to the entitlement.

Customer outcomeDefensible access decisions across sensitive insurance functions, with reviewer, rationale, timestamp, and evidence retained.
UnderwriterQuote · bind · referral · override
Claims AdjusterClaim · reserve · settlement · payment
Claims SupervisorHigher authority · approvals · overrides
Billing SpecialistRefunds · payment changes · adjustments
Producer ServicesAgency users · producer administration
Finance / ActuarialReporting · models · financial data
Quarterly Claims Access Review
High-impact entitlements
61% complete
Claim Settlement · $250K Authority
J. Patel · Senior Adjuster · last role change 18 months ago
Review
Claim Payment Override
M. Rivera · Claims Supervisor · used this month
Keep?
Legacy CAT Adjuster Access
Contractor · CAT assignment ended 94 days ago
Revoke?
Give the reviewer employment context, system, entitlement, business authority, ownership, and exception history—not just a technical permission code.
Stage 03 · Remediate

Prove that revoked insurance authority was actually removed.

A review decision does not reduce risk until the access change is completed. Keep fulfillment and reconciliation tied to the original certification.

Customer outcomeTraceable closure for revoked claims, policy, billing, producer, privileged, and third-party access.

Core application change

Route the removal to the application administrator or supported automated target and retain the fulfillment status.

External / delegated access

Track termination of producer, TPA, adjuster, contractor, or vendor access that may sit outside normal employee provisioning.

Reconciliation

Confirm that the entitlement no longer appears in the source data and retain evidence of closure.

Stage 04 · Standardize

Turn cleaned insurance access into repeatable job patterns.

After review cycles remove stale access, use the production data to identify stable patterns and separate normal job access from true exceptions.

Customer outcomeFaster onboarding, cleaner requests, and fewer one-off entitlements accumulating over time.

Access Analysis

Find common access combinations for claims, underwriting, billing, producer services, finance, actuarial, and IT populations.

Access Templates

Create reusable access packages for stable job patterns while leaving unusual authority as a separately approved exception.

Segregation of Duties

Identify combinations that should receive additional scrutiny—for example where transactional, approval, payment, or administrative authorities overlap.

Stage 05 · Automate

Control the moments when insurance access changes fastest.

Insurance has access events that do not fit a simple employee-onboarding model. Permanent staff, producers, contractors, TPAs, acquisition teams, and catastrophe-response workers can all need different access durations and approvals.

Customer outcomeNew and temporary access follows a governed path instead of becoming the next quarterly-review cleanup.
New hire

Underwriter onboarding

Assign standard job access, route higher underwriting authority separately, and keep exceptions visible.

Role change

Adjuster promoted to supervisor

Add new approval authority while identifying old or conflicting permissions that should be removed.

CAT event

Temporary adjuster surge

Grant contractors or independent adjusters time-bound access for a defined catastrophe-response period, then remove it when the assignment ends.

Third-party exit

TPA or vendor relationship ends

Revoke named users, shared/service accounts, integrations, and other residual access tied to the relationship.

Access Request

Let employees and approved external populations request applications, entitlements, templates, or time-bound authority through defined approval paths.

Lifecycle & fulfillment

Use authoritative identity events to drive supported provisioning/deprovisioning and controlled ticket-based fulfillment for systems that still require an administrator.

Stage 06 · Monitor

Govern the identities that are not traditional employees.

Core insurance workflows increasingly depend on service accounts, integration identities, bots, APIs, external users, and AI-enabled processes. Ownership and access review need to extend beyond workforce identities.

Customer outcomeA governed inventory of human, non-human, and emerging AI identities with ownership and risk context.

Service & integration accounts

Classify and assign owners to service accounts connecting policy, claims, billing, data, payment, and document workflows.

IdentityWatch

Add usage context to supported identity environments to surface dormant access and make certification decisions more evidence-based.

AI identities & agents

Track ownership and access as AI-enabled agents begin to act within underwriting, claims, service, and operational workflows.

Stage 07 · Prove

Map access governance to the insurance cybersecurity control environment.

Identity governance is one part of a broader insurance information-security program. The value is being able to show who had access, why it was appropriate, what was removed, how third-party access was controlled, and what evidence supports the program.

Customer outcomeA repeatable access-control evidence trail that can support cybersecurity, risk, compliance, internal audit, and regulatory examination work.
NAIC Model Law #668

Access controls and evidence are explicit parts of the model.

  • Protect against unauthorized access to nonpublic information.
  • Use access controls that permit access only to authorized individuals.
  • Assess the effectiveness of key safeguards, controls, systems, and procedures at least annually.
  • Maintain audit trails and include cybersecurity risk in enterprise risk management.
  • Exercise due diligence over third-party service providers.
  • Maintain records supporting annual compliance certification where the adopted law requires it.

State adoption and implementation can differ. The insurer should validate the law and regulatory requirements applicable in each jurisdiction.

NYDFS 23 NYCRR Part 500

For covered insurers in New York, access review is a direct control requirement.

  • Limit user access to what is necessary for the person’s job.
  • Limit and protect privileged accounts.
  • Review user access privileges at least annually and remove access that is no longer necessary.
  • Promptly terminate access after personnel departures.
  • Address third-party service-provider access and security.
  • Use risk assessment as the basis for the cybersecurity program.

Applicability depends on whether the insurer or insurance entity is a Covered Entity under New York law.

Questions an insurance access program should be able to answer

Make the evidence specific to insurance operations.

Who can quote, bind, issue, endorse, cancel, or override policy decisions?
Who can approve claim settlements, payments, reserve changes, or other elevated claims actions?
Who can change payment details, issue refunds, or adjust customer balances?
Which producers, agencies, TPAs, independent adjusters, contractors, or vendors still have access?
Which terminated or reassigned users still retain privileges in a core insurance application?
Who has privileged access to systems containing policyholder, claimant, beneficiary, health, or financial information?
Which service accounts and API identities connect policy, claims, billing, payment, document, and data systems—and who owns them?
When a reviewer revoked access, can you show the fulfillment task and evidence that the entitlement was actually removed?
The SecurEnds insurance adoption path

Start with a control. Expand around the insurance lifecycle.

Phase 1

User Access Reviews

Policy, claims, billing, underwriting, producer, finance, identity, and other in-scope systems.

Phase 2

Access Governance

Requests, temporary access, lifecycle, templates, SoD, and controlled fulfillment.

Phase 3

Identity Security

Usage context, service accounts, non-human identities, AI identities, and identity risk.

Phase 4

Risk & Compliance

IT risk, third-party/vendor risk, policy, controls, findings, remediation, and evidence.

Make the demo insurance-specific

Bring one policy, claims, or billing access problem—not a generic IAM requirements list.

We’ll show how the users, entitlements, business authorities, reviewers, revocations, and evidence would work in SecurEnds, then map the expansion path for requests, lifecycle, temporary access, non-human identities, and third-party governance.

Insurance walkthrough

Show us the access behind policies, claims, payments, and customer data.

Start with one real access-review population and the systems that are hardest to govern today. We’ll show the review, remediation, evidence, and the next governance step without forcing a full-suite implementation.