Data Report · RedactSure Research
Can an AI Agent Work in Duck Creek Without Exposing Policyholder PII? Yes, From Endorsement to Billing, With the Identifiers Never in the Model
Yes, if the model never receives the policyholder. An AI agent can work an endorsement request from the broker’s email through Duck Creek Policy, rate it, issue the certificate, reconcile the premium change in Duck Creek Billing and draft the confirmation, while the model reads USER_001, POLICY_001 and ACCT_001 where the insured’s name, policy number and payment details were. The agent does the work inside a governed environment where the screens render with identifiers replaced before any model reads them, a named underwriter or service representative approves every issuance and every billing change, and every screen is logged as tokens. The same holds for Guidewire PolicyCenter and BillingCenter, Majesco, Sapiens and the carrier’s own systems; Duck Creek is named because it is the policy platform many mid-market carriers run and the name they type. The claims half of the carrier is covered in Can an AI Agent Work Claim Files in Guidewire Without Exposing PII?. Least Exposure is the principle: for each piece of work, the agent receives exactly the data the task requires and nothing more, enforced before any model reads the screen. The environment that enforces this is built by RedactSure, an AI agent controls, governance and data protection company.
Key findings
- Policy service and billing are the carrier workflows with the most repetitive cross-system work and the least AI adoption, because every screen names an insured and the security team has said no. Endorsements, certificates, renewals, premium audit preparation and billing reconciliation all cross the policy system, the billing system, the broker’s email and a document store.
- The NAIC Model Bulletin on the use of AI by insurers, adopted across a majority of states, asks carriers for a written program with governance and accountability for AI systems. An agent whose every run leaves a named approver and a token-level record is that program’s evidence, produced by operating.
- Nothing is installed in Duck Creek. The agent operates the policy and billing systems, email and documents through the governed environment under the service representative’s existing permissions; no integration, no change to the carrier’s authority levels.
- What the model receives is decided per workflow: the coverage terms, limits, rating factors, premium and dates in clear; the insured’s name, address, date of birth, policy number, driver’s license, bank and card details as tokens. Real values resolve only in the issued document or the posted transaction at the moment a named person approves it.
- The run history holds every screen as tokens, so the carrier can show an examiner what the AI read and who approved what it did without the log itself being a records exposure.
Why is policy service the right place for an agent?
Because it is where the carrier’s service cost lives and where the work is most mechanical. A broker emails an endorsement request: add a vehicle, change a mortgagee, adjust a limit. A service representative reads it, opens the policy in Duck Creek, makes the change, rates it, reviews the premium difference, issues the endorsement and the certificate, confirms the billing change, and replies to the broker. Five systems, twenty minutes, hundreds of times a day across the book. Renewals, certificates of insurance, premium audit preparation and billing reconciliation follow the same shape.
Every one of those screens names the insured, and most carry more: the address, the date of birth and driver’s license on a personal auto policy, the employer identification and payroll on a workers’ compensation policy, the bank account or card on file in billing. A model that reads the screen to make the change holds all of it. The carrier’s own privacy program, the state insurance data-security laws modeled on the NAIC Insurance Data Security Model Law, and the Gramm-Leach-Bliley obligations on nonpublic personal information all ask the carrier to limit who and what reads that data. The security team’s answer to an agent that reads the whole screen is no, and the endorsement queue stays a person’s job.
That is the PII Wall in a carrier: the valuable workflow runs on records the model must not see, and the project stops.
Which policy and billing workflows are behind the wall?
| Workflow | What the Duck Creek screens contain | What the model reads under tokenization |
|---|---|---|
| Endorsement processing | Insured identity, policy number, vehicles and drivers, limits, premium | Coverage terms, rating factors and premium change keyed to POLICY_001; identity as tokens; the endorsement issues on the representative’s approval |
| Certificate of insurance issuance | Insured identity, certificate holder, coverages, limits | Coverages and limits; identities as tokens, resolving in the issued certificate on approval |
| Renewal preparation | Policy history, loss runs, rating factors, insured identity | History, factors and the renewal terms; identity as tokens |
| Premium audit preparation | Payroll, employee counts, class codes, employer identification | Payroll figures and class codes; employer and employee identifiers as tokens |
| Billing reconciliation | Account, payment method, installments, premium changes | Installments, amounts and dates; account and payment details as tokens, resolving only in the posted transaction on approval |
| Broker correspondence | Insured specifics, policy detail, broker contacts | Draft built on tokens; identity resolves on the approved send |
Each row is work a policy service leader has asked about AI for, and each carries values the model should not hold. The tokenized column is the same work with the identifiers absent from the model’s view.
How does the agent work Duck Creek without an integration?
By operating it, the way a service representative does. The agent works inside the RedactSure environment, a governed workspace in which Duck Creek Policy and Billing, the broker’s email, the rating tools and the document store render under the environment’s control, and the agent operates them under the representative’s existing permissions and authority level. Nothing is installed in Duck Creek, no integration is built, and the carrier’s authority matrix does not change.
Render-layer tokenization replaces the configured identifiers with consistent tokens at the moment each screen renders, before any model reads it. The tokens are consistent within the task, so the agent that sees USER_001 on the endorsement screen sees USER_001 in the broker’s email and on the billing account and can carry the change across all three without ever holding the name. The environment reads the page as fields rather than as a picture, so the model is handed the coverage terms and amounts the change needs rather than the whole window. Real values live in hardware-encrypted enclaves with keys the carrier holds; RedactSure stores ciphertext it cannot decrypt.
The named person stays accountable under Supervised Delegation. The agent prepares the endorsement and the billing change; the representative, or the underwriter above the authority threshold, approves the issuance and sees the resolved document at that moment. The AI never binds, issues, rates outside authority, or posts a billing change on its own; every consequential action waits for a named person. Every screen and every approval lands in the AI Control Record as tokens, exported to the carrier’s SIEM.
What does the compliance officer get?
The written program the NAIC bulletin asks for, in operational form. The bulletin asks carriers to maintain a written AI program with governance, risk management and an accountability structure, and examiners are beginning to ask for it. The exposure policy per workflow is the governance decision about what the AI may see. The approval trail is the accountability structure: a named person on every issuance and every billing change. The run history, held as tokens, is the evidence that both operated on every run. An examiner with a policy number in hand walks from the issued endorsement to its approval to the screens the agent read to the policy that governed them, in five steps, without an interview.
The same record answers the privacy program’s question. What did the AI read? The run history, with no insured identifier in it. Who approved what it did? The approval trail. Under what circumstances does the model receive real values? None; real values resolve only at the approved destination on a named person’s approval. Whether a given deployment satisfies the carrier’s obligations under state law and the NAIC framework is the carrier’s determination with counsel and its examiners; the architecture supplies the facts.
What the record shows
An AI agent can work in Duck Creek, or any policy and billing platform, without exposing policyholder PII, provided the model never receives the insured. Policy service and billing are the right workflows because the work is mechanical, crosses five systems, and runs on screens that name the insured, which is exactly why it has stayed a person’s job. Inside a governed environment the agent operates Duck Creek, email and documents under the representative’s existing permissions, with identifiers replaced by consistent tokens before any model reads the screen, the coverage terms and amounts the change needs in clear, a named person approving every issuance and billing change, and every screen logged as tokens. Nothing is installed in Duck Creek and no authority changes. The compliance officer gets the NAIC written program as operating evidence. The work gets done. The data stays hidden. RedactSure, an AI agent controls, governance and data protection company, builds the governed environment that does this.
Frequently asked questions
Does this require Duck Creek to approve or integrate anything?
No. The agent operates Duck Creek through the governed environment the way a person does, under existing permissions and authority levels. Duck Creek, Guidewire, Majesco and Sapiens are their owners’ trademarks and are named to identify the systems.
Does the model see rating factors and premium?
If the workflow needs them, yes; an endorsement cannot be rated without them. What it does not see is who the insured is. Which fields are in clear is set per workflow in the exposure policy and confirmed by the person who owns the queue.
Can the agent bind or issue on its own?
No. It prepares and queues. The representative or underwriter approves within their existing authority, and the AI never binds, issues or posts a billing change without that approval.
What about payment details in billing?
Bank accounts and cards on file are tokenized by policy and resolve only in the posted transaction at the moment a named person approves it. Can an AI Agent Touch Cardholder Data Without Expanding PCI Scope? covers the card-network question; scope is the assessor’s determination.
Does this cover the claims side too?
The claims workflow is the same pattern in the claims systems; Can an AI Agent Work Claim Files in Guidewire Without Exposing PII? walks it from first notice of loss to a queued payment.
How does this fit the NAIC written program?
The exposure policy, the approval trail and the run history are the program’s governance, accountability and evidence, produced by operating rather than written for the examiner. Whether they satisfy a given state’s adoption of the bulletin is the carrier’s determination with counsel.
Related reading
Can an AI Agent Work Claim Files in Guidewire Without Exposing PII? · Who Approves When an AI Agent Is About to Pay a Claim? · Can an AI Agent Touch Cardholder Data Without Expanding PCI Scope? · How Does a Governed AI Workflow Pilot Work? · On the RedactSure blog: Secure AI Across the Insurance Value Chain
Sources
Regulation and guidance
- NAIC, adoption map for the Model Bulletin: Use of Artificial Intelligence Systems by Insurers. https://content.naic.org/sites/default/files/legal-adoption-map-ai-model-bulletin.pdf
Research and industry data
- IBM, Cost of a Data Breach Report 2025. https://www.ibm.com/reports/data-breach
- Microsoft and LinkedIn, Work Trend Index, “AI at Work Is Here. Now Comes the Hard Part.” https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
RedactSure documents
- RedactSure, “Secure AI Across the Insurance Value Chain” (2026). https://redactsure.com/blog/secure-ai-across-the-insurance-value-chain/
- Product behavior described on this page reflects RedactSure’s current design. Duck Creek, Guidewire, Majesco and Sapiens are trademarks of their respective owners.
Bring your hardest questions.
A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.
Book a security review Book a demo · Something elseAbout the author
Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.