Cloud API producerCodes access management

This topic only applies to ClaimCenter.

The producerCodes strategy is one of the access strategies that manages access to third-party data. The following topic describes the base configuration behavior of this strategy.

The producerCodes strategy determines which claims the user can access by looking for a cc_producerCodes claim in the JWT. This claim contains a list of producer codes that represent the producer. The user can access any claim where the claim's policy's producer of service is associated with one of the producer codes in the JWT.

Note: InsuranceSuite does not require producer codes to be unique across producers. For example, suppose you have two producers: Allrisk Insurers and Allied Assistance. Within InsuranceSuite, both of those producers could have a producer code of "All-001". If two producers have the same producer code, then information that is associated with one producer would be visible to calls made by the other producer.

To ensure that each producer can see only the information related to their policies, Guidewire recommends that all producer codes across producers are set to unique values.

Resource types with filtered access

This strategy controls access to third-party data for the following resource types:

  • Claim
  • ClaimContact
  • Incident
  • AssessmentContentItem
  • Exposure

The producerCodes strategy does not limit access to policies. This is because policy information is not considered third-party data from the viewpoint of a producer. If a producer has access to a policy, it is because they are managing the claim on behalf of the insured and are entitled to privileged access to the policy.

Internal "hasAccessOn<Resource>" methods

This strategy uses the following internal methods:

Method Returns true if...

user.​hasProducerAccessOnClaim

The producer code for the claim's policy's producer of service is one of the producer codes in the JWT.
user.​hasProducerPrivilegedAccessOnClaimContact The ClaimContact has at least one of the ClaimContact roles specified in ProducerAccesibleRoles.​yaml.

user.​hasProducerPrivilegedAccessOnIncident

The incident has an associated ClaimContact with at least one of the ClaimContact roles specified in ProducerAccesibleRoles.​yaml.

user.​hasProducerAccessOnExposure

The exposure's claimant also has one of the roles specified in ProducerAccesibleRoles.​yaml.

ClaimContact role yaml files

This strategy uses the following files:

  • ProducerAccessibleRoles.yaml
Warning: Do not delete or rename the ProducerAccessibleRoles.yaml file itself. Doing so will cause the producerCodes resource access strategy to not behave as expected.

accessiblefields.yaml files

This strategy uses the following files:

  • restricted.accessiblefields.yaml