COVU Service Network Carrier Access Authorization
Document ID: `covu.service-network.carrier-access-authorization.v1.0` Version: 1.0 Release date: July 30, 2026 Provider: COVU Inc.
This Service Network Carrier Access Authorization (this “Authorization”) supplements the COVU Service Network Services Agreement and accepted Service Orders for the Agency. It authorizes COVU to use one identified carrier account for accepted Service Network work. It does not authorize a new service lane, charge, licensed act or consequential insurance decision.
This Authorization becomes effective for an Agency and carrier only when a current Agency owner or administrator accepts it with an immutable Carrier Access Summary. The Carrier Access Summary identifies the Agency, carrier, nonsecret access profile and permissions being authorized and is incorporated into this Authorization.
1. Carrier Access Summary
The Carrier Access Summary must display and preserve:
- the Agency legal name and Agency ID;
- this Authorization's document ID, version and SHA-256;
- the carrier and portal or system;
- a nonsecret carrier-account or producer identifier;
- the Service Network Access Profile ID and nonsecret credential-record ID;
- whether the credential is a dedicated Service Network login or a shared Agency login;
- the account holder or named-user role;
- the MFA method and responsible role, without any secret;
- each selected permission;
- the current Service Network Services Agreement and applicable Service Order references;
- the effective date and revocation method; and
- a canonical configuration digest.
An omitted, unreadable, internally inconsistent or stale Carrier Access Summary does not authorize COVU access.
2. Recommended access method
COVU recommends that the Agency create a separate named COVU or Service Network login whenever the carrier permits one. A dedicated login improves attribution, auditability, least privilege, revocation and carrier compliance.
A dedicated login is not mandatory under this Authorization. If the Agency uses a shared credential, the Agency gives the additional representation in Section 5.
3. Available permissions
The Carrier Access Summary may authorize one or more of these permissions:
- view account, customer, policy and transaction information;
- retrieve or download records and documents;
- upload documents supplied or approved by the Agency;
- enter or update Agency-approved factual information;
- submit an Agency-approved service request;
- communicate with the carrier about an accepted Service Network task; and
- another narrowly described permission accepted through the Carrier Access Summary.
COVU may use a selected permission only:
- for a task within an accepted Service Order;
- at the Agency's documented instruction;
- through the identified Service Network Access Profile;
- where the Agency and assigned person have the required authority;
- within verified carrier, licensing, appointment and state requirements; and
- using approved COVU personnel or Service Providers subject to confidentiality, least-privilege access and audit controls.
4. Actions not authorized
Unless a later Service Order and Carrier Access Summary expressly and lawfully add an action after the required verification, COVU may not:
- quote, bind, issue, rewrite, change, cancel or nonrenew coverage;
- change limits, deductibles, insureds, drivers, vehicles, properties or beneficiaries;
- make a coverage, underwriting, claims, fraud, legal or eligibility decision;
- accept carrier terms, warranties or attestations requiring the Agency's independent judgment;
- transfer premium, commissions, refunds or other money;
- change carrier appointments, producer records or banking details;
- solicit, sell or place insurance;
- use the account for another agency or purpose; or
- perform an act requiring an unverified license, line of authority, appointment or carrier permission.
This Authorization grants limited access authority. It is not a power of attorney, producer appointment, carrier appointment, transfer of the Agency's book or general authority to bind the Agency.
5. Agency representations
The Agency represents and agrees that:
- it controls or is authorized to use the identified carrier account;
- it may lawfully authorize COVU's selected access and Service Network use;
- the carrier permits the selected access method and Agency delegation;
- the credential is not another person's credential used without permission;
- the Agency maintains the carrier relationship, appointments, producer records and account permissions required for accepted tasks;
- the Agency will provide accurate instructions and will not ask COVU to exceed the selected permissions;
- the Agency will keep its users, MFA contacts and escalation contacts current;
- the Agency will promptly notify COVU if the carrier, account, permission, appointment, employee relationship or authority changes; and
- the Agency will not use this Authorization to circumvent a carrier security control, named-user requirement or prohibition.
If the Carrier Access Summary identifies a shared Agency login, the Agency additionally represents:
> The Agency chose to share this credential with COVU for the selected Service Network permissions. The Agency confirms that the carrier permits the credential and access arrangement. COVU recommended a separate named Service Network login where available.
Agency acceptance cannot override carrier rules. COVU may require a named account, carrier form, additional authentication, written carrier approval or another access method before use.
6. COVU responsibilities
COVU will:
- use the account only for accepted tasks and selected permissions;
- limit access to approved personnel or Service Providers who need it to perform the task;
- protect the credential under the Security Exhibit;
- avoid reproducing secrets in logs, receipts or task records;
- record each access against the Agency, carrier, task, person or system and current Authorization;
- follow the accepted Service Order's review and escalation rules;
- stop or escalate before a prohibited, consequential or unverified act;
- notify the Agency of a credential failure, material access concern or known loss of authority; and
- stop new access promptly after revocation.
COVU may refuse or suspend access when carrier terms, credential health, licensing, appointment, security, customer-harm or legal requirements cannot be verified.
7. Standing authority and tasks
This is a standing authorization. The Agency does not need to accept a new Carrier Access Authorization for each task performed:
- for the same carrier and Service Network Access Profile;
- within the selected permissions;
- under an accepted Service Order; and
- before revocation or a material change.
Each task still requires the operational instruction and evidence required by the Service Order. Operational approval is not a new contract.
8. Credential changes
A password or MFA-method rotation does not require fresh acceptance if the carrier, account, credential mode, permissions and legal scope remain unchanged.
Fresh acceptance or revalidation is required before:
- adding a different carrier;
- changing the credential from dedicated to shared;
- materially broadening permissions;
- enabling automated or unattended portal activity not previously disclosed;
- using a different carrier account with different authority;
- adding a Service Order that requires access outside the selected permissions; or
- resuming after a known loss of carrier or Agency authority.
9. Revocation
The Agency may revoke this Authorization in OS Lite or through the revocation method in the Carrier Access Summary. Revocation:
- blocks new COVU access to the identified profile;
- pauses queued and unfinished tasks that require it;
- does not undo completed authorized activity;
- does not eliminate properly earned charges;
- preserves required access, consent, security, billing and legal records; and
- does not delete a credential that the Agency continues to use internally.
Deleting a dedicated Service Network credential automatically revokes the related access profile. Removing a shared credential from Service Network does not prevent the Agency from retaining it for its own use.
10. Electronic acceptance
The final review screen must require an unselected checkbox displaying:
> I represent that I am a current owner or administrator authorized to bind the Agency identified in the Carrier Access Summary. The Agency authorizes COVU and its approved Service Network personnel to use the identified carrier access profile on the Agency's behalf, solely for accepted Service Network tasks and the permissions in the Carrier Access Summary. The Agency confirms that it controls or may use this account and may authorize this access. If a shared credential is selected, the Agency confirms that the carrier permits the arrangement.
The authorization button must read:
> Authorize Service Network carrier access
COVU will preserve the Carrier Access Summary, canonical configuration digest, current Service Network Agreement and Service Order references, exact document version and SHA-256, displayed acceptance language, checkbox state, accepter identity and role, authority attestation, timestamp, supersession and revocation in the agreement ledger and provide a downloadable receipt.
The credential secret is not part of the agreement receipt.
Acceptance alone does not log into the carrier, route a task, create a charge, verify a license or appointment, or authorize an action outside the selected permissions.