Playbook, insurance broker

Getting into the portal, and who is entitled to be in it

Documents are issued to a portal rather than posted, so being locked out is not an inconvenience, it is not having the certificate somebody has asked you for. The awkward part is that access is not really a technical question. On a commercial policy the login belongs to whoever arranged it, and once that person has left the company the request arriving is not about a password at all, it is about who is now entitled to the policy documents.

Why this is not the general answer

The handling pattern for account access problems holds across every trade. What follows is the part that does not.

  • What sits behind the login is the schedule, the wording and the certificate, so the person locked out is usually locked out of proving something to a third party rather than out of a preference screen.
  • One policy can involve more than one login: your own document portal, an insurer's site for claims or documents, and a finance provider's site for the instalments, and the customer does not know which of the three they are looking at.
  • On a commercial account the credential sits with a named individual, so a colleague asking for access is asking the firm to change who may act on the policy, which is a decision about authority rather than a reset.
  • Confirming that an email address is registered tells whoever asked that a policy exists at this broker, which matters more than it sounds when somebody is trying to establish what cover a business carries.

How it arrives

  • i cannot log in to get my certificate
  • our office manager has left who can access the account now
  • which portal do i use for my documents
  • can you email me my schedule instead
  • does my login work for the insurer site as well
  • i never got the invite to the portal

What has to be indexed for this to work

Material behind this answer
Which portal holds whatYour document portal, any insurer site, and the finance provider's collections page, with what lives on each and the address of each. Naming them separately ends most of these before they become a support request.
How access is granted and to whomWho is set up on a commercial account, how a second user is added, and what you require before the named contact is changed. This is an authority procedure and the page should read like one.
The route for a document somebody needs todayHow a certificate or a schedule is obtained when the portal will not cooperate, and what you need before you send one. There has to be a route that does not depend on a login working.
What the assistant may confirm about an accountWrite the boundary down: no confirmation that an address is registered, that a policy exists, or that somebody is a client. Without it, a helpful answer quietly becomes a disclosure.

The reply

A reply worth copying
There is usually more than one login in play, so it helps to know which you mean: our document portal holds your schedule, wording and certificate, the insurer's site is used for claims on some policies, and monthly payments sit with the finance provider [1]. I cannot see accounts, reset anything, or confirm whether an address is registered. If a document is needed today there is a route that does not depend on the portal [2], and if the person who held the login has left the business, that is a change of contact rather than a reset and it goes through the team [3]. Leave me your name and an email and somebody will pick it up.

It disambiguates the three logins first, because a fair number of these are people at the wrong site altogether. It refuses to confirm whether an address is registered and says so out loud rather than quietly not answering. And it separates the departed colleague case, because treating that as a password problem is how a broker hands a stranger a company's insurance documents.

Where it stops

The trigger. The visitor asks for a reset, asks whether an account exists, or says the named contact has left and somebody else needs access.

The handover, worded
I cannot reset anything or confirm what accounts exist. Leave me your name, an email and the company or policy you mean, and the team will check who is authorised and sort the access out properly.

It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.

Never say this here

Out of bounds

  • Never confirm that an email address, a policy or a client account exists, because that discloses a business relationship to whoever happens to be asking.
  • Never send or offer to send a schedule or a certificate, since the assistant cannot attach a document and cannot verify who is on the other end.
  • Never treat a departed employee's login as a password problem, as the real question is who is authorised on the account now.
  • Never say which insurer somebody is with, because that sits on their own schedule and is not for an unverified visitor.

Questions

Could it reset a password if we connected the portal?
No. It reads material you give it and has no write access to any system, so a reset always ends at your team or at the portal's own recovery route.
Somebody needs a certificate for a contract today. What should it do?
Give the route that does not need the portal, immediately, and hand over with a note that it is urgent. A certificate held up by a login is a commercial deadline missed, and it deserves a faster path than a general enquiry.
Is it a problem that it cannot tell clients from strangers?
It is the reason the boundaries above exist. Because it cannot verify anybody, everything it says has to be safe to say to a stranger, which is a useful test to run over your published material as well.

Keep reading

Try it on your own material

Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.