10.2 An Example Scenario

This example scenario discusses about various requirements specific to consumer access management of an organization.

Let us assume Acme Inc. is a life insurance provider that provides individual and group insurance products to its customers. It has nationwide agents that sell and service insurance products. It also sells insurance products through the online portal. It uses SaaS services such as ServiceNow, Salesforce, DocuSign, and LexisNexis to provide services to its consumers and agents.

Acme Inc. serves the following two types of online users:

  • Consumer: A person who buys the insurance products. In this example, Carol is a consumer.

  • Insurance Agent: A person who sells products of Acme Inc along with the products from other companies. An agent needs elevated privileges. In this example, Aaron is an agent. He needs privileges to access the information about commission details, view new products, view clients’ insurance information, and access to additional services such as a service ticket in ServiceNow.

The Access Manager B2C portal caters to the following requirements of Aaron and Carol in this scenario:

Registration through any of the following ways:

  • As a new user using the registration page

  • As an agent

  • Using social accounts

Agent Activation through the following way:

  • Using B2C customer center to create agent’s username

  • Verification code is sent to agent’s email ID

  • Agent sets password using username and verification code

Login through any of the following ways:

  • Using the default login page

  • Using social accounts

  • Through a federated account

  • Using an Advanced Authentication mechanism

Account Management to perform the following actions:

  • View and delete applications

  • View and edit profile details such as name and phone number and preferences

  • View and manage devices

  • Manage passwords

Privacy and Consent Management to perform the following actions:

  • Decide what information they want to share

  • Manage privacy and consents

  • Delete account and erase all personal information

For information about how to configure B2C access management for this scenario, see Section 10.13, Business To Consumer Wizard: Sample Configuration.