Overview of Cloud API resource access strategies

Strategies and IDs

A resource access strategy is a set of logic that identifies which resources a caller can access.

A resource access ID is a string that identifies either who the caller is or what the caller owns.

Some resource access strategies expect a single resource access ID. Other resource access strategies allow for an array of resource access IDs.

For each call, resource access is determined by executing the resource access strategy using the resource access ID as input. For example, in PolicyCenter, suppose a given resource access strategy states "the caller can access information related to accounts they own". And suppose, for a given call, the resource access ID is account number 464778619. This would mean the following:

  • The caller can access resources that are related to account 464778619.
  • The caller cannot access resources that are related to accounts other than 464778619.

The list of resource access strategies

The base configuration includes the following resource access strategies:

Strategy name Persona using this strategy Resource access ID is... Grants access to... More information
cc_contactAuthorizationIds (ClaimCenter) Insureds and third-party claimants An array of contact authorization IDs Resources where at least one of the specified contacts has an appropriate business relationship with the resource The contactAuthorizationIds strategy
cc_producerCodes (ClaimCenter) Producers of service A set of one or more producer codes Resources associated with claims where the producer code for the producer of service on the claim's policy is one of the provided producer codes The producerCodes strategy in ClaimCenter
cc_gwabuid (ClaimCenter) Claims service provides The ABUID (Address Book Unique IDentifier) of the service provider contact Resources associated with claims for which the provided ABUID is associated with one of the claim's service providers
cc_username (ClaimCenter) Internal users A ClaimCenter user name Resources this internal user could see in ClaimCenter based on their associated Access Control Lists (ACLs).
cc.​service (ClaimCenter) Trusted service-to-service application Not applicable All resources The service strategy
pc_accountNumbers (PolicyCenter) Account holders (including anonymous users who have created an account) An account number Resources associated with the account, including its jobs and policies
pc_producerCodes (PolicyCenter) Producers A set of one or more producer codes and roles. Resources associated with the accounts, jobs, and policies for the given producer and the role. The producerCodes strategy in PolicyCenter
pc_username (PolicyCenter) Internal users A PolicyCenter user name Resources this internal user could see in PolicyCenter based on their associated Access Control Lists (ACLs).
pc.​service (PolicyCenter) Trusted service-to-service application Not applicable All resources The service strategy
bc_username (BillingCenter) Internal users A BillingCenter user name Resources this internal user could see in BillingCenter.
bc_contactAuthorizationIds (BillingCenter) Account owners, primary payers, and invoice item payers An array of contact authorization IDs Resources where at least one of the specified contacts has an appropriate business relationship with the resource The contactAuthorizationIds strategy
bc.​service (BillingCenter) Trusted service-to-service application Not applicable All resources The service strategy
bc_producerCodes (BillingCenter) Producers An array of one or more producer codes, as strings Resources where at least one of the specified producer codes has an appropriate business relationship with the resource The producerCodes strategy in BillingCenter
default Callers who have been authenticated but specify no resource access strategy with the call Not applicable Typically just metadata resources only (such as API definitions)
unauthenticated (ClaimCenter and BillingCenter) Callers who have not been authenticated Not applicable Typically just metadata resources only (such as API definitions)
unauthenticated (PolicyCenter) Callers who have not been authenticated Not applicable API definition metadata and the endpoints to create accounts. (The account endpoints are used by anonymous users who may want to quote and potentially bind a policy.)
Note: In ClaimCenter, there is also a cc_policyNumbers resource access strategy. This strategy expects the JWT to have an array of policy numbers. It gives access to resources associated with claims whose policy number is one of the provided policy numbers. Guidewire recommends insurers use the cc_contactAuthoriationIds strategy instead of the cc_policyNumbers strategy. The cc_contactAuthoriationIds strategy is more robust, as it provides additional configuration options and is appropriate for both insureds and third-party claimants.

The JWT identifies which resource access strategy to use by listing the strategy name in the scp token claim. If the given strategy requires resource access IDs, then the JWT also contains a token claim whose name is the strategy name and whose contents are the resource access IDs.

For example, suppose that a given call in PolicyCenter is using the pc_accountNumbers resource access strategy with a resource access ID of 464778619. The JWT would include the following.

"scp": [
  "pc_accountNumbers"
],
"pc_accountNumbers": [
  "464778619"
]

Determining a call's resource access strategy

Resource access strategies are assigned by internal code as described in the following table. For calls made by services with user context, two resource access strategies are assigned, one at the service level and one at the user level. For all other types of calls, only one resource strategy is assigned.

Strategy name This is assigned to a call when...
xc_producerCodes

Any of the following are true:

  • The JWT's scp token claim contains xc_producerCodes, where xc is the application code (cc, pc, or bc).
  • The call includes a user context header, and the header includes a xc_producerCodes token claim.
xc_username

Any of the following are true:

  • The call is using basic authentication.
  • The JWT's scp token claim contains xc_username, where xc is the application code (cc, pc, or bc)
  • The call includes a user context header, and the header includes a xc_username token claim, or
  • The JWT specifies a client ID that was mapped to a service account.
xc.​service The JWT's scp token claim contains xc.​service, where xc is the application code (cc, pc, or bc).
cc_contactAuthorizationIds (ClaimCenter)

Any of the following are true:

  • The JWT's scp token claim contains cc_contactAuthorizationIds.
  • The call includes a user context header, and the header includes a cc_contactAuthorizationIds token claim.
cc_gwabuid (ClaimCenter)

Any of the following are true:

  • The JWT's scp token claim contains cc_gwabuid.
  • The call includes a user context header, and the header includes a cc_gwabuid token claim.
cc_policyNumbers (ClaimCenter)

Any of the following are true:

  • The JWT's scp token claim contains cc_policyNumbers (and it does not contain a cc_contactAuthorizationIds token claim).
  • The call includes a user context header, and the header includes a cc_policyNumbers token claim (and it does not contain a cc_contactAuthorizationIds token claim).
(If the JWT contains both a cc_policyNumbers token claim and a cc_contactAuthorizationIds token claim, then the cc_contactAuthorizationIds strategy is used.)
pc_accountNumbers (PolicyCenter)

Any of the following are true:

  • The JWT's scp token claim contains pc_accountNumbers.
  • The call includes a user context header, and the header includes a pc_accountNumbers token claim.
bc_contactAuthorizationIDs (BillingCenter)

Any of the following are true:

  • The JWT's scp token claim contains bc_contactAuthorizationIDs.
  • The call includes a user context header, and the header includes a bc_contactAuthorizationIDs token claim
default The caller has been authenticated, but the JWT specifies no resource access strategy.
unauthenticated The caller has not been authenticated.