Compliance & audit

Insurance agency compliance with an auditable trail

Every sensitive action recorded, every credential encrypted, every view scoped to a role. AgencyGrid gives agencies the audit trail and access controls that carrier, E&O, and CMS reviews expect.

Agencies handle sensitive data: producer records, commission detail, and for Medicare shops, protected health information. Carriers, CMS, and E&O carriers all expect that data to be access-controlled and every consequential action to be traceable after the fact.

AgencyGrid builds those controls into the platform rather than bolting them on. Access is scoped by role across your agency hierarchy, credentials are encrypted at rest, and a tamper-evident audit log records who did what and when.

An append-only audit trail

Compliance depends on being able to answer a simple question: who saw this, and who changed it? AgencyGrid keeps an append-only audit log that captures sensitive events, including support impersonation (“view as agent”) and access to protected health information. Records are added, never edited or deleted.

When a carrier audit or an internal review asks what happened, the answer is a query, not an archaeology project.

  • Append-only log: entries cannot be altered or removed
  • Impersonation (“view as agent”) recorded every time
  • PHI-access events captured for Medicare books

Access scoped to the role

The safest data is data the wrong person never sees. AgencyGrid scopes every view to the user’s place in the hierarchy: agents see their own book, managers see the downline they manage, and the agency sees the whole grid. Carrier SFTP credentials and other secrets are encrypted at rest, with the master key held only in deployment environment variables, never in the database or the logs.

What you get

Controls auditors expect

Role-scoped access

Each user sees only their slice of the hierarchy: agent, team, or org.

Append-only audit log

Tamper-evident record of sensitive actions, including impersonation.

PHI-access tracking

Access to protected health information is logged for Medicare books.

Encrypted credentials

Carrier secrets encrypted at rest; master key kept out of the database.

FAQ

Common questions

What compliance controls does AgencyGrid provide?

Role-scoped access across the hierarchy, an append-only audit log of sensitive actions (including impersonation and PHI access), and encryption of carrier credentials at rest: the controls carrier, E&O, and CMS reviews typically expect.

How does the audit log work?

The audit log is append-only: entries are recorded and cannot be edited or deleted. It captures consequential events such as support “view as agent” impersonation and access to protected health information, so activity is traceable after the fact.

Is protected health information (PHI) tracked?

Yes. For Medicare and other health books, access to protected health information is recorded in the audit log, giving you a defensible record of who viewed sensitive data and when.

How are carrier credentials protected?

Carrier SFTP credentials and other secrets are encrypted at rest, and the master encryption key lives only in deployment environment variables, never in the database and never written to logs.

Keep an audit trail you can stand behind

Role-scoped access, encrypted credentials, and an append-only log of every sensitive action.