

Industries · Insurance
Insurance platforms serve a crowd: underwriters, claims handlers, brokers, third-party agencies, and policyholders, all touching the same policies and claims. Permit decides what each of them can do, record by record, without a code change every time the org chart moves.

“It took two weeks to move from our in-house solution to production with full permission management.”
Dor TabakuliFull Stack Team Leader, Honeycomb InsuranceUnderwriter, senior underwriter, underwriter for this state, agency admin for that broker. Each exception becomes a role, until the role list is the problem. Honeycomb Insurance hit this wall before moving to fine-grained policies.
Brokers and third-party agencies need their own submissions and policies, and nothing belonging to the agency down the street.
Binding limits, lines of business, territories, and claim amounts decide whether an action is allowed. Those rules change far more often than you ship code.
Claims and underwriting files carry personal, financial, and sometimes health information. Access has to be narrow, and it has to be provable.
Model the relationships your business already runs on, agency to agent to policy to claim, and let policy decide.
ReBAC grants access through relationships, so an agent sees the insurance policies written through their agency, and an agency admin manages only their own people.
Encode binding authority, territory, line of business, and claim thresholds as attributes, instead of inventing a role for each combination.
Operations adjusts roles and permissions in a no-code editor, and every change is saved as policy code. Honeycomb adds and edits roles this way instead of assigning developers.
Pricing models, document processors, and AI agents are authorized with the same rules as the humans they work for.
Every decision is logged with its reason, so you can show who opened a claim file and under which rule.
An agent tries to bind above their binding authority. Illustrative data.

How a permission decision is made
State insurance data security laws, NYDFS, and HIPAA all expect the same foundation: access limited to authorized people, and a record of it.
| Framework | What it asks for | How Permit helps |
|---|---|---|
| NAIC Insurance Data Security Model Law (#668) | Place access controls on information systems so only authorized individuals reach nonpublic information. | Default-deny rules decide access to each insurance policy and claim, and every decision is logged. |
| NYDFS 23 NYCRR 500.7 | Limit access privileges to nonpublic information, review them at least annually, and restrict privileged accounts. | Roles, relationships, and conditions live in one place, so a review looks at policy instead of scattered code. |
| HIPAA Security Rule, §164.312(a) and (b) | Access controls and audit controls for systems holding protected health information. | Fine-grained access to health-related claim data, decision logs for audit, and a BAA available for regulated workloads. |
| GLBA safeguards, as adopted by state insurance regulators | Protect the security and confidentiality of customer information, including limiting who can access it. | Attribute and relationship policies enforce need-to-know for each policyholder. |
Framework summaries are paraphrased for orientation and are not legal advice. No authorization vendor makes you compliant on its own. Permit helps you implement and evidence the access controls these frameworks test; your audits remain your own.
“Permit allows us to maintain the complexity and fine tuning with minimal effort on the code and easy configuration. The team at Permit is fantastic, real experts, with endless willingness to help. I was amazed by their openness to feedback and how quickly they evolved their product from very good to excellent.”
Nimrod SadotCo-founder and CTO, Honeycomb Insurance“Using Permit, the amount of time it takes to develop and maintain our product’s permissions is a tiny fraction of what it would have been building it on our own.”
Model agencies, agents, and policies as related resources. Relationship-based policies then grant access through those links, so access follows the book of business automatically as agents and policies change.
Yes. Changes made in the editor are saved as reviewable policy code, and policy guards control which roles and resources each team may change.
It depends on your model. At Honeycomb Insurance, a single developer took the team from its in-house system to production on Permit in two weeks.
Permit supports HIPAA-regulated workloads and provides a BAA where applicable. Decision points can run inside your network, so health data can stay there, with only opaque identifiers leaving it.
Yes. Honeycomb manages permissions for thousands of users and machine identities across dozens of resources, under the same policies.
Tell us what you are authorizing and where it runs. We come to the call with a model of how Permit would enforce it.