Documentation
Platform Manuals
Everything you need to administer, use, and understand the value of InsuranceCompliance.ai — for platform admins, agency owners, and compliance officers.
Admin Manual
For the platform owner / workspace administrator responsible for payments, automation, data, and security.
1. Platform Overview
InsuranceCompliance.ai is a public, no-login-required platform that turns live public insurance-regulatory data into a scored compliance posture for any agency. Visitors run a free Instant Scan; subscribers get year-round monitoring, daily AI briefings, and a unified compliance workspace. The admin role manages payments, secrets, scheduled workflows, backend functions, and data.
2. Account & Access
The site is public — visitors need no account. Admins sign in at /login. To add a team member, use the invite flow (admin role only) — users cannot be inserted directly. Auth pages (/login, /register, /forgot-password, /reset-password) are built in and maintained by the platform. Admins manage user roles from the Users admin.
3. Stripe Payments (Live Mode)
Checkout runs through the createCheckoutSession backend function, which guards the request origin and creates a Stripe Checkout session. The stripe-webhook function receives payment events at https://insurancecomplianceai.base44.app/functions/stripe-webhook. Required secrets: STRIPE_SECRET_KEY, STRIPE_PUBLISHABLE_KEY, STRIPE_WEBHOOK_SECRET. Products and prices are managed in the Stripe Dashboard; the frontend blocks checkout inside an iframe and redirects to the published app.
4. Secrets Management
All credentials live in Settings → Secrets, never in code. Active secrets: STRIPE_SECRET_KEY, STRIPE_PUBLISHABLE_KEY, STRIPE_WEBHOOK_SECRET (live), STRIPE_TEST_* (test), CRON_SECRET (secures scheduled workflow runs), RESEND_API_KEY (transactional + briefing email). Rotate a key by updating the secret in place; webhook re-registration requires deleting STRIPE_WEBHOOK_SECRET first.
5. Scheduled Workflows
Two workflows run automatically: "Daily Audit Briefing" (6:00 AM Central) calls dailyAuditBriefing — it gathers tasks, licenses, updates, complaints, and breaches, asks the LLM for a 60-second executive briefing, and emails every user. "Daily Deadline Alerts" calls sendDeadlineAlerts for overdue/upcoming tasks. Manage state (activate / deactivate / archive) from the Workflows dashboard. Both accept CRON_SECRET for scheduled execution and admin auth for manual runs.
6. Backend Functions
generateAgencyScan — public, origin-guarded LLM scan with web search. createCheckoutSession / stripe-webhook — payments. dailyAuditBriefing — admin or CRON_SECRET. sendDeadlineAlerts — deadline email. niprSync, amsSync, regulatoryFiling — require the user to supply their own API credentials in Settings before they return live data. Test any function from its dashboard page or via test_backend_function.
7. Data & Entity Management
Core entities: Regulation, EnforcementAction, BreachEvent, Producer, ComplianceTask, Document, Report, Policy, Training, Complaint, Vendor, AISystem, CarrierAppointment, ProducerLifecycle, ComplianceROI, and more. Row-Level Security restricts each entity — most allow owner + admin. Seed or bulk-load records via CSV/Excel import. Use the Document Review Queue (/review-queue) to classify uploaded files one at a time. AuditLogEntry records key actions for traceability.
8. Integrations & Connectors
NIPR, AMS, and SERFF filings need user-provided API credentials to go live. Workspace OAuth connectors (Gmail, Google Calendar, Outlook, LinkedIn, etc.) can power agent and workflow automation once authorized. Manage connectors from Settings → OAuth Connectors; authorize shared connectors or register workspace-owned OAuth apps as needed.
9. Monitoring & Maintenance
Use the preview tools to verify routes render and interactions fire before publishing. Watch the AuditLogEntry entity for create/update/delete/review activity. Keep the navigation lean — retire modules with no data rather than leaving empty buttons. Publish from the builder when a change set is verified.
