Hannah Lowe

Fenmoor Specialty Underwriting / B-Brain – Security Review

Callcompleted

Fenmoor Specialty Underwriting: documents logo Fenmoor Specialty Underwriting: documents · 2025-10-31 10:45

Nadia Osei, IT Security Lead, confirmed in the second review session that SSO and SCIM are Enterprise only, so Growth has manual leaver removal. Several answers remain open and she gave no sign-off date.

What was said

What this says

Current to 10 Oct 26

Nadia Osei, IT Security Lead, confirmed in the second review session that SSO and SCIM are Enterprise only, so Growth has manual leaver removal. Several answers remain open and she gave no sign-off date.

What happened: Hannah Lowe walked Nadia Osei through access control. She confirmed that SSO and SCIM are not available on Growth and that leavers are removed manually by an admin.

Customer view: Nadia said capacity providers expect named accounts tied to the identity provider. She wants two labelled positions, Growth today and Enterprise, and will not give a sign-off date until providers have seen the pack.

Commercial: Hannah described the Enterprise gap and the upgrade without pressing it. The review is a real driver for Enterprise, but Nadia is treating the gap and the sale as separate.

Watch: Ten open items remain, including MFA enforcement, log retention, role change logging and the number of admins. Unanswered items could stall the review.

AI · claude-sonnet-5-5 · 10 Oct 2026

Themes

Current to 9 Oct 26
Theme
SSO gap, security review
Importance
upsell
Sentiment
mixed
Voice
decision-maker

Who was there

B-Brain

Them

Follow-up

Next steps

Current to 9 Oct 26
  • Hannah Lowe to send the covering email listing provider documents, the two-position description and the compensating control wording.
  • Hannah Lowe to get answers from the security lead on MFA, log retention, role change logging and connector credentials.
  • Hannah Lowe to get the admin count from Daniel Okafor for the follow-up.

Risks

Current to 9 Oct 26
  • Growth has no SSO or SCIM, and leavers keep access until an admin removes them manually.
  • Ten open items, including MFA enforcement and log retention, are unanswered and could delay sign-off.
  • Nadia Osei gave no sign-off date and waits on the capacity providers.

Opportunities

Current to 9 Oct 26
  • Moving to Enterprise would bring SSO and SCIM and close the leaver gap the capacity providers care about.
  • A clear two-position write-up could support an upgrade case without a hard sell.

Transcript

  1. Hannah Lowe
    Hannah Lowe None
    Morning, Nadia. Can you hear me alright?
  2. Nadia Osei
    Nadia Osei None
    Good morning, Hannah. Yes, clearly. Can you hear me? My headset has been temperamental this week.
  3. Hannah Lowe
    Hannah Lowe None
    Loud and clear. How was the weekend that wasn't, I mean, how's the week ended up?
  4. Nadia Osei
    Nadia Osei None
    Ha. Fine, thank you. Rather a lot of questionnaires, I imagine similar to yours. Shall I begin with the open items from last time?
  5. Hannah Lowe
    Hannah Lowe None
    Please do. I've got my copy next to me.
  6. Nadia Osei
    Nadia Osei None
    Thank you. From session one I have five. One, the written statement on the model path. Two, confirmation of what operational information B-Brain receives. Three, the backup wording. Four, the enlarged key on the diagram. Five, support access, which was deferred to today. I received the revised diagram and the table of responsibilities, and the key is larger, so item four is closed.
  7. Hannah Lowe
    Hannah Lowe None
    Good. On one to three, I did get answers, and they're in the document I sent over earlier this week. Would you like me to take them in order, or would you rather read them first and come back with questions?
  8. Nadia Osei
    Nadia Osei None
    I've read them, and I have questions, but I'd like them walked through so they're on the recording. I can't sign off a control on a verbal answer, but I want the verbal answer to match the paper.
  9. Hannah Lowe
    Hannah Lowe None
    That's sensible. So, the model path. The short answer is that the processing stays within the boundary described in the note, and the longer answer is in the note itself, which I'd ask you to treat as the authority rather than anything I say now. I'm going to read you only what the note says, so there's no drift.
  10. Nadia Osei
    Nadia Osei None
    Please. And I'd ask that you say so if there is anything the note doesn't cover.
  11. Hannah Lowe
    Hannah Lowe None
    Of course. The note describes what is sent, where it's processed, and what is retained. It's explicit about the retention part. What it doesn't cover is the detail of the model provider's own internal arrangements, which are described in the provider's documentation rather than ours. I've said that in the note, because I'd rather you see the limit of what we can evidence.
  12. Nadia Osei
    Nadia Osei None
    That's the correct approach, though it does mean I will need the provider's documentation in the pack. Can you tell me which documents to request?
  13. Hannah Lowe
    Hannah Lowe None
    I'll list them by name in a covering email and I'll put that in writing today, so you have it before the next session.
  14. Nadia Osei
    Nadia Osei None
    Thank you. Items two and three?
  15. Hannah Lowe
    Hannah Lowe None
    Two is counts and status, so whether a connector loaded and how many records were indexed. Not the content. That's confirmed by our security lead. Three, backups, is as I said last time. The data and the index are objects in your account, so recovery depends on your Snowflake configuration. We hold the deployment definition and can redeploy. We don't hold a copy of your content.
  16. Nadia Osei
    Nadia Osei None
    Good. I'll close two and three subject to receiving them as signed statements rather than as a note. I'll need that in the questionnaire as a formal response.
  17. Hannah Lowe
    Hannah Lowe None
    Understood, I'll get the statements on the right template. Shall we go on to access control? That's today's subject, and I know SSO is the one you've been waiting for.
  18. Nadia Osei
    Nadia Osei None
    It is, yes. Let me put my numbered questions again. One, how do individual users authenticate. Two, how are roles defined and who can change them. Three, what happens when someone leaves. Four, can you evidence who asked what, and when. Five, and I suspect this is the sensitive one, what is the position on single sign-on at the tier we are currently on.
  19. Hannah Lowe
    Hannah Lowe None
    Right, thank you. Straight to the last one first, because it shapes the rest, and I'd rather be direct. Single sign-on and SCIM provisioning are part of the Enterprise tier. On Growth, which is where you are today, accounts are managed in the brain directly. So no, you don't have SSO today.
  20. Nadia Osei
    Nadia Osei None
    Thank you for being direct. That does matter, because our capacity providers expect named accounts to be tied to our identity provider. May I ask what the position is for leavers on Growth?
  21. Hannah Lowe
    Hannah Lowe None
    To be precise, it's a manual step. Someone with the admin role removes the user. There's no automatic de-provisioning from your identity provider, because that's what SCIM does, and that arrives with Enterprise.
  22. Nadia Osei
    Nadia Osei None
    Understood. So today a leaver continues to have an account until an administrator removes it. How many administrators do you have in the brain at present?
  23. Hannah Lowe
    Hannah Lowe None
    I don't have the figure in front of me, and I'd rather not guess. I'll ask Daniel Okafor, who looks after the account, and put it in the follow-up. It's a fair question, because the number of admins and who they are is part of the control.
  24. Nadia Osei
    Nadia Osei None
    Please. For the audit trail, I need to be able to say who holds that role.
  25. Hannah Lowe
    Hannah Lowe None
    Yes. Now let me answer your first question properly, authentication. On Growth, users sign in to the brain with credentials managed in the brain. On Enterprise, they would sign in through your identity provider, and you control the multi-factor policy there, which I think is the main attraction for you.
  26. Nadia Osei
    Nadia Osei None
    It is. May I ask about multi-factor authentication on Growth, where there is no identity provider? Is it enforced, or is it optional?
  27. Hannah Lowe
    Hannah Lowe None
    I'm going to stop there, honestly, because I don't want to overstate it. I know what the product does by default, but I'm not certain I can state the enforcement position for the tier as a control. I'll check with our security lead and put the answer in the pack. I'd rather say that than hand you something you can't rely on.
  28. Nadia Osei
    Nadia Osei None
    That's acceptable, and I would add it as open item six. Please can you also tell me whether the answer differs by tier?
  29. Hannah Lowe
    Hannah Lowe None
    Yes, I'll cover both tiers in the same answer so you can see them side by side.
  30. Nadia Osei
    Nadia Osei None
    Thank you. Roles, then. Question two.
  31. Hannah Lowe
    Hannah Lowe None
    So there are a small number of roles in the brain, and then there's the underlying Snowflake layer, which is yours. I want to keep those two apart, because people blur them. The brain's roles decide what a person can do in the brain, so who can see which pages, who can build dashboards, who administers connectors. The Snowflake roles decide what the brain's service can read in your account at all. The second sets the outer limit, and the first works inside it.
  32. Nadia Osei
    Nadia Osei None
    That's a helpful framing. So if my team restricts a table in Snowflake, the brain cannot show it, regardless of what a brain role says?
  33. Hannah Lowe
    Hannah Lowe None
    That's the design, yes. Access you haven't granted to the brain's service is not something a brain role can create. I'll document that with an example, because it's the sort of statement that's much stronger with a worked case.
  34. Nadia Osei
    Nadia Osei None
    Please use something from our own world. Submissions with restricted claims information, for example, where only some people should see them.
  35. Hannah Lowe
    Hannah Lowe None
    Good, I'll use that. I'll need to be careful about it not looking like we've seen your real data, so I'll describe it generically, a table of claims information that your team has chosen to restrict.
  36. Nadia Osei
    Nadia Osei None
    Quite right. Who can change a role? That was the second half of question two.
  37. Hannah Lowe
    Hannah Lowe None
    Admins in the brain. Which comes back to the number of admins, and to the point that on Growth it's a manual process with no approval workflow around it. That's something I'd say plainly in the pack rather than leave you to find. If you want a record of role changes, that's your fourth question, the logging.
  38. Nadia Osei
    Nadia Osei None
    Yes, go on. What is logged, and for how long?
  39. Hannah Lowe
    Hannah Lowe None
    The questions people ask are recorded, that's how we measure usage. What I can't give you from memory is the retention period, nor whether role changes are logged in the same place. I'll put both as questions to our security lead. Don't let me gloss that.
  40. Nadia Osei
    Nadia Osei None
    I won't. So item seven, retention period and the scope of the log. And item eight, whether role changes appear in it. I'll write them down.
  41. Hannah Lowe
    Hannah Lowe None
    Thanks. While you write, I'll say one thing about the Enterprise side, so it's on the record. Moving up would bring SSO and SCIM, which closes the leaver gap and ties authentication to your identity provider. It also brings an executive sponsor on our side. I'm not telling you that to sell, only because it answers the gap I've just described.
  42. Nadia Osei
    Nadia Osei None
    I understand, and I'm grateful that you described the gap before the solution. I'm treating them as separate things. The gap exists today on Growth, and the review should say so.
  43. Hannah Lowe
    Hannah Lowe None
    Agreed. It will say so.
  44. Nadia Osei
    Nadia Osei None
    Now, a question about timing, because the business keeps asking. If SSO is the control our capacity providers want, does the review wait on the upgrade?
  45. Hannah Lowe
    Hannah Lowe None
    That's your call and your capacity providers' call, not mine. What I can do is describe the control as it stands today and as it would stand under Enterprise, as two clearly labelled positions. Then you can show them whichever is relevant, or both.
  46. Nadia Osei
    Nadia Osei None
    Two positions would be the most honest presentation. I'll ask for that. And for the avoidance of doubt, I still won't give a date for sign-off until the providers have seen the pack.
  47. Hannah Lowe
    Hannah Lowe None
    Understood. I haven't asked for one. Daniel mentioned the end of the year as the timeline on our side, but that's a commercial plan, and I'd keep it separate from your review.
  48. Nadia Osei
    Nadia Osei None
    Good. I'll keep it separate too. Right, back to leavers. Is there anything between manual removal and SCIM, like a report of inactive users, that I could use as a compensating control until we decide?
  49. Hannah Lowe
    Hannah Lowe None
    That's a smart thing to ask. I'm not certain that exists as a report, and I'm not going to claim it does. What I can offer is that your admins can see the list of users, so a periodic review against your leavers list is possible, and I can describe that as a procedure. It isn't automatic, though, and I'd label it as a manual compensating control.
  50. Nadia Osei
    Nadia Osei None
    A manual compensating control, clearly labelled, is something I can work with. Please add a sample frequency suggestion if you're comfortable, but make it a suggestion, not a requirement.
  51. Hannah Lowe
    Hannah Lowe None
    I'll suggest it without prescribing it. Is there anything else on access?
  52. Nadia Osei
    Nadia Osei None
    One last point, on service accounts. The connectors, the brain's own service. What credentials do they use to read our source systems, and where are they kept?
  53. Hannah Lowe
    Hannah Lowe None
    Another one I want to answer in writing, because it touches how secrets are stored. I'll bring it to the next session with the answer from our security lead, rather than give you half of it now.
  54. Nadia Osei
    Nadia Osei None
    Item nine. Thank you. Let me read back the open items, so we agree what is outstanding.
  55. Nadia Osei
    Nadia Osei None
    Carried from session one, one to three, awaiting signed statements. New from today, six, multi-factor enforcement by tier. Seven, log retention and scope. Eight, whether role changes are logged. Nine, connector credentials and where they're kept. And the number of admins, which I'll call ten. Have I missed anything?
  56. Hannah Lowe
    Hannah Lowe None
    No, that matches mine. I've also got the covering email listing the provider documents, the two-position description of access control, and the compensating control wording. I'll send all of that, with the open items marked as pending where I don't yet have answers.
  57. Nadia Osei
    Nadia Osei None
    Thank you. Session three, next Friday?
  58. Hannah Lowe
    Hannah Lowe None
    Next Friday, yes. I'll confirm the topic by email so you can pass it to whoever else needs to join. Thanks for your patience on the ones I couldn't answer today, Nadia.
  59. Nadia Osei
    Nadia Osei None
    Not at all, that's what makes the pack usable. Kind regards, Hannah. Speak next week.
  60. Hannah Lowe
    Hannah Lowe None
    Thanks, Nadia. Bye for now.

B-Brain is a fictional company; every organisation and person here is invented. Built by site/build_site.py from the site tree, data as of Fri 9 Oct 2026. Help & Support

Help & Support

Open as a page

Help & Support

B-Brain is one place to read everything the company knows about its customers: the CRM, calls, emails, support tickets, product usage, invoices, documents, news and HR. Every page is built from those systems and the data is current to Fri 9 Oct 2026.

How to use the site

How to ask

Press Ask Brain in the header. Type a question, or pick one of the examples.

The site itself does not call an AI model; answers in Claude come from the same figures you see here.

What the data covers

DataRecords
Organisations75
People at customers290
B-Brain staff40
Calls784
Email threads1,169
Support tickets449
Documents477
Deals117
Invoices101
Events49
News items56

Data as of Fri 9 Oct 2026. Text marked AI was written by the brain from the records listed in its made-from link; an AI output that cannot cite its evidence is refused and the previous text kept. Where two systems disagree (for example a contract and the CRM), the key facts show both values and mark the difference.

B-Brain is a fictional company: every organisation, person and figure here is invented for this demonstration.

Who to contact

Email support@b-brain.example or talk to your B-Brain account team. Tell us the page address and what looked wrong; a screenshot helps.

Ask B

Ask B

B-Brain · read-only