Skip to content
AskFlorence
Main Navigation ArchitectureFlorence AIAgentsMembersAgent PlatformValidationInfrastructure

Appearance

Sidebar Navigation

Overview

Home

Glossary

System Architecture

Consumer & Agent Flow

Florence AI

Overview

Principles

Runtime

Tool surface

Adding a tool

Tool registry

Knowledge: SBC scenarios & CSR

Voice

Evals & observability

Provider risk & portability

Outage playbook

Roadmap

Build plan

Agents

Overview

Workflows & pain points

Members

Overview

Medicaid coverage gap

Carriers

Overview

Marketplaces

Overview

Agency

Overview

Regulations

Overview

Agent Platform

Overview

Auth Architecture

MongoDB Permissioning

Compliance Model

Data Models

Data Sources

Overview

CMS Marketplace API

CMS dependency map

PUF Data

State Subsidies

SBE Ingestion Playbook

SBE State Watchouts + Decisions

CA Phase C/D Playbook

NY Phase C/D Playbook

Validation

Overview

Methodology

APTC Formula

California 2026

New York 2026

CAPS Formula

Scenario Results

Infrastructure

Account Inventory

AWS Setup Runbook

AWS Organizations

CloudTrail

GuardDuty

Security Hub

Config

CloudFront + WAFv2

Data sources & ingest

Phase 4 DNS

Change Log

Vulnerability Management

MongoDB Setup

Access Control

Data Classification

Documentation Hosting

Post-deploy Smoke

Development

Preflight (local CI mirror)

Testing strategy

Compliance

Overview (auditor entry point)

SOC 2 Control Mapping

HIPAA Control Mapping

CMS EDE Appendix A Mapping

Risk Assessment

Encryption Policy

Data Retention Policy

Privacy Impact Assessment

Consent Capture & Versioning

Incident Response Plan

Access Control Policy

Marketing vs. Portal Analytics

Vendor / Subprocessor Register

Dependency Vulnerability Policy

BAA / Compliance Evidence

Compliance-Automation Integration

Compliance-Automation Vendor Evaluation

Penetration Test Reports

Architecture

Portal entry handoff

Mobile app strategy

Deferred architecture decisions

Session cookie architecture

Share flows

Decisions (ADRs)

Index

0001 — Atlas project isolation

0002 — Append-only audit log

0003 — Narrow-scoped Mongo users

0004 — Cross-cluster Atlas PrivateLink

0005 — Delayed-job architecture

0006 — Mongo user simplification

0007 — Terraform owns ECS task def

0008 — E2E testing strategy

0009 — Self-hosted analytics + observability (superseded)

0010 — PostHog HIPAA Cloud (supersedes 0009)

Runbooks

Security Incident Response

Break-Glass Root Login

Onboard Team Member

Offboard Team Member

Atlas user provisioning

Deploy via Terraform (ENG-277)

Rollback via Terraform (ENG-277)

S3 data bucket migration (planned Phase 11)

Access Reviews

2026-Q2 Review

Session log

Index

2026-04-23 — Phase 10 DNS cutover

2026-04-22 — Phase 8 prod AWS mirror

2026-04-22 — Phase 7 Atlas VPC peering

2026-04-22 — Phase 6 CloudFront + WAF

2026-04-21 — Phase 5 staging go-live

2026-04-17 — Atlas staging

Briefs

Index

Member portal plan (ENG-187)

2026-04-16/17 handoff

2026-04-17 Atlas handoff

System briefing (2026-04-17)

Creative AdBundance proposal brief

Creative AdBundance analytics brief

ElevenLabs RN integration research

Policies

Overview

On this page

Agent Platform — Overview ​

Status: Living document. Last updated April 17, 2026. Version: Phase 1 shipped (v0.4.1). Phase 2 next.


What this is ​

AskFlorence's agent platform is a parallel product track to the consumer experience. It recruits licensed ACA insurance agents and agencies, gives them a portal where they receive pre-qualified leads with pre-filled applications, and lets them review + submit enrollments in 5-6 minutes each. Recurring commissions are paid for the life of each enrolled member.

Two partnership models:

ModelSplit (net to agent)Effort per enrollmentDesigned for
Full Service50/50 ($11.50 net PMPM)30-60 minutes — call, gather info, guide, submitRelationship-heavy agents
Submit-Ready80/20 ($4.60 net PMPM)5-6 minutes — review pre-filled package, verify, submitVolume scale agents

Despite the lower per-member rate, Submit-Ready agents typically out-earn Full Service by 2-3x at scale because they can submit 5-10x the applications.

Terminology ​

  • Agent — individual licensed producer. May be solo, or part of an agency.
  • Agency — organization with multiple agents. Agency owner/manager can invite their team to join AskFlorence under the agency.

No "broker" wording is used in any agent-facing content. Pre-April-2026 documents may still say "broker"; all new content says "agent" or "agency."

Ship order (phase roadmap) ​

PhaseStatusWhatWhere
1✅ Shipped v0.4.1/agents landing + /agent-onboarding waitlistCurrent (Vercel)
2Next/agent-discovery 11-screen research surveyCurrent (Vercel), after /privacy ships
3Ops taskMongoDB permissioned users (app_writer_survey etc.)MongoDB Atlas
4PlannedAWS migration (Issue #47)Blocks Phase 5+
5Post-AWSAgent portal: auth, NIPR, ID verify, dashboard, adminNew infra
6Post-Phase-5Activation + Tier-2 security before leads flowNew infra

Why Phase 5+ waits for AWS: agent data includes PII (NPN, name, email), and eventually member PHI flows through activated agent accounts. CMS EDE (Enhanced Direct Enrollment) audits look back at how you've been operating for months, so we build on SOC 2 / HIPAA / EDE-ready foundations from day one rather than migrate under audit pressure later.

Current state (what's live at askflorence.health/agents) ​

  • Public marketing landing page, 8 sections, indexable
  • Mobile-intentional design with full 100svh hero, scroll cue, hamburger nav, floating CTA
  • Waitlist form at /agent-onboarding collecting: name, role (individual agent vs agency owner/manager), company or agency name, email, phone, NPN (validated 6-10 digits)
  • Ops notifications email to agents@askflorence.health on every signup
  • Cross-promotion to the discovery survey (once it ships) from the waitlist success screen

No auth yet. No real portal yet. Both come in Phase 5.

Related documents ​

  • Auth Architecture — Tier 1 / Tier 2 / super-admin auth paths and session design
  • MongoDB Permissioning — DB user scopes, migration path, production exit criteria
  • Compliance Model — SOC 2 / HIPAA / CMS EDE alignment, audit log, consent capture
  • Data Models — collections, indexes, retention policies

Source of truth ​

The full compliance-first architecture plan lives at ~/.claude/plans/jolly-forging-thacker.md on Taha's machine. These docs pages are the checked-in version of the decisions already locked in.

Pager
Previous pageOverview
Next pageAuth Architecture

AskFlorence Internal Documentation. Not for public distribution.

AskFlorence

Internal Documentation

Access restricted. Not for public distribution.