Skip to main content

What your carrier sees

Every report your carrier receives is a snapshot: evaluated once, frozen, fingerprinted, and never edited. Your Insurance Exchange page shows the same snapshot under What your carrier will see, from the same stored row, so the preview is not an approximation. When the report is released, the carrier reads that row and a document rendered from it, and the Carrier access history on your page records each read.

When reports happen

A report is produced for each reporting period in the agreement, after the period has fully ended. The first one therefore arrives one full period after acceptance; until then the page says no report has been generated yet. The evaluation runs overnight on your records as they stand at that point. Anything you fix during the day is reflected in the next evaluation, and an obligation that comes back into good standing shows as such on the next report, not retroactively.

Release follows on the agreed cadence. If the carrier has chosen manual release, the report waits for the carrier's own two-person decision, and you can read it on your page while it waits.

The headline

  • Score, 0 to 100, higher is better, with a band (low, moderate, high or critical) describing the risk the score represents. Low is the good one.
  • Confidence: how complete the data behind the score was. When too little is known, the score and band are withheld entirely and confidence reads unknown. The report never fills a gap with a default.
  • Degraded: shown when inputs were stale or unreachable during evaluation. The affected controls are reported as unknown; degraded inputs never resolve to compliant.
  • Score components: fulfillment (how many obligated controls are verified met, which carries the most weight), evidence (linked, fresh, reviewed), posture (open failing cloud checks) and timeliness (obligations on time). Each shows its value and weight, or no data if it could not be computed.
  • Since the previous report: how many controls improved, regressed or held, and how many are new to scope. A first report says it is a baseline instead of reporting zeros.
  • Gaps: plain-language notes on what limited the evaluation.

Each obligated control

Under each obligation, one row per control:

ColumnWhat it means
VerdictMet: assessed compliant, directly or through a reviewed crosswalk, with any required assurance in place. AI-inferred: satisfied only through a crosswalk mapping nobody has reviewed yet; it counts, but for less. Not met: assessed non-compliant, an open critical or high finding, or assurance below the required level. Unknown: nothing trustworthy to decide on, so it counts against you until there is. N/A: excluded under an exclusion the carrier consented to.
Since last reportImproved, regressed, changed, unchanged (with how many days it has sat there), or first report.
ProvenanceWhere the verdict came from: a direct assessment, a crosswalk, and so on.
AssuranceThe control's assurance level at evaluation, where the obligation requires one.
Evidence ageAge in days of the most recent evidence linked to the control.

Below the row, when there is something to say:

  • Your own written justification for the control, with who assessed or attested it, when, and by what method. This is the sentence an underwriter can actually weigh, which is why it crosses.
  • Each piece of supporting evidence by title, module and date linked. Under a sealed artifacts disclosure level it carries a content hash. A document's hash lets the carrier verify a copy if one is ever provided. A questionnaire answer has no file, so its hash pins the answer's wording only, and the report says so next to it.
  • Not reviewed on any item no person has approved yet, which is where AI-drafted answers sit until someone reviews them.
  • A count of items that support the requirement but cannot be content-hashed, stated rather than folded into the total.

The report ends with the disclaimer text from the agreement, the formula version, and the snapshot's fingerprint.

The carrier's copy

The carrier reads the report in its own Carrier Portfolio and can download it as a self-contained document rendered from the frozen snapshot. Before a download link is issued, SolveGRC re-checks the stored document against its recorded hash. A mismatch refuses the download and records an integrity event on both organizations' audit chains, which appears in your access history as artifact integrity check failed.

Carrier access history

Every time the carrier views your portfolio entry, opens a report or downloads one, the event is written to your organization's own tamper-evident audit chain and listed under Carrier access history with a timestamp. It is your record of what was accessed and when, kept on your side.

What is never in the report

Documents, raw findings, cloud inventory, controls outside the obligations, and anything the accepted terms did not cover. If the relationship is paused, the carrier's reads stop until it resumes. Reports released before a pause remain with the carrier for the retention period in the terms.