Skip to main content

Accept an agreement

An agreement is the whole arrangement between you and your carrier as SolveGRC will enforce it: which controls you must keep in good standing, by when, how often the carrier hears about them, and how much of your evidence a report may describe. Nothing about your organization reaches the carrier until an agreement version is accepted, and every report afterwards is checked against the accepted terms before it is produced and again before it is released.

Before it can happen

  • The exchange is a plan add-on. If it is not enabled for your organization, the review panel says so and the accept button stays off until it is.
  • Accepting is a consent act. It needs an organization administrator or a compliance officer, in a session protected by two-factor authentication. A weaker session cannot accept.
  • The person who proposed the version on the carrier side cannot be the one who accepts it, even if they belong to both organizations.

Reading the panel

When a carrier sends a version, it appears at the top of your Insurance Exchange page as Agreement awaiting your acceptance, with the carrier's name and the version number. Everything on the panel is drawn from the sent version itself, so it is exactly what you would be agreeing to:

  • Reporting cadence. How often a report is produced (every 30 days, every 90 days, and so on) and the dates the agreement runs between.
  • Grace and notice. How many days past a due date an obligation may sit in grace before it becomes a reportable failure, the minimum notice you receive first, and how long a carrier's extension offer stays open before it lapses unanswered.
  • Evidence disclosure. Summary only means a report carries verdicts, scores and evidence counts per requirement, with no document names. Summary + sealed artifacts means each requirement also lists its supporting items by name, date linked and content hash. The files themselves never cross under either level, and raw findings and cloud inventory never cross at all.
  • Retention. How long released reports remain available to the carrier after the relationship ends.
  • Control obligations. Each obligation with its due date, the number of controls it covers, and the assurance level it requires, if any.
  • Terms. The carrier's written terms, in full.

Accepting, declining, and versions

Accept agreement sends back a fingerprint of exactly the terms you were shown. If the version has changed in any way since the panel rendered it, acceptance is refused rather than binding you to terms you did not read. On success the obligations appear on your page with their due dates, and the first reporting period starts counting from the acceptance.

Decline records an optional reason for the carrier and closes the version. The carrier can send another.

A sent version is frozen. If the carrier wants different obligations, a different cadence or a different disclosure level, that is a new version, and it arrives for acceptance the same way. Until you accept it, reporting continues under the version you last accepted.

Once accepted, the frameworks the obligations name are activated in your organization if they were not already, so the obligated controls can be assessed and backed with evidence like any other control. See Activate and scope a framework.

Not-applicable controls

If a control genuinely does not apply to you, marking it not applicable in Frameworks is not enough on its own for the report. The carrier has to have agreed to the exclusion in the accepted terms. A not-applicable control the carrier never consented to is reported as unknown, not silently dropped, so a score cannot be raised by excluding things. Ask the carrier to include the exclusion in the next version.