Cloud API producerCodes access management
This topic only applies to ClaimCenter.
The producerCodes strategy is one of the access strategies that manages access to third-party data. The following topic describes the base configuration behavior of this strategy.
The producerCodes strategy determines which claims the user can access by looking for a cc_producerCodes claim in the JWT. This claim contains a list of producer codes that represent the producer. The user can access any claim where the claim's policy's producer of service is associated with one of the producer codes in the JWT.
To ensure that each producer can see only the information related to their policies, Guidewire recommends that all producer codes across producers are set to unique values.
Resource types with filtered access
This strategy controls access to third-party data for the following resource types:
- Claim
- ClaimContact
- Incident
- AssessmentContentItem
- Exposure
The producerCodes strategy does not limit access to policies. This is because policy information is not considered third-party data from the viewpoint of a producer. If a producer has access to a policy, it is because they are managing the claim on behalf of the insured and are entitled to privileged access to the policy.
Internal "hasAccessOn<Resource>" methods
This strategy uses the following internal methods:
| Method | Returns true if... |
|
|
The producer code for the claim's policy's producer of service is one of the producer codes in the JWT. |
user.hasProducerPrivilegedAccessOnClaimContact
|
The ClaimContact has at least one of the ClaimContact roles
specified in ProducerAccesibleRoles.yaml. |
|
|
The incident has an associated ClaimContact with at least one of
the ClaimContact roles specified in
ProducerAccesibleRoles.yaml. |
|
|
The exposure's claimant also has one of the roles specified in
ProducerAccesibleRoles.yaml. |
ClaimContact role yaml files
This strategy uses the following files:
ProducerAccessibleRoles.yaml
ProducerAccessibleRoles.yaml file itself. Doing so will cause
the producerCodes resource access strategy to not behave as expected.accessiblefields.yaml files
This strategy uses the following files:
restricted.accessiblefields.yaml