skip to content

A broker integrator archived a year of explained claim-triage replies. What can they build, and what stays out of reach?

level: seniorimportance: should knowfreq 33%

answer

  1. three columns, not two
  2. richer target per example, fewer examples needed
  3. coverage is their own book of business
  4. a copy of a slice, not the parameters
  5. every call was contractually legitimate

basics

~20 s

They hold claims paired with scores and per-field sensitivity rows — enough to fit a close functional stand-in over the segment their own book covers, and to read off which fields drive referrals. Not the parameters, not behaviour outside that segment, and not yet a changed decision.

solid answer

~50 s

The archive is a supervised dataset with an unusually rich target: for each claim, the score the model gave and a description of how the model responded to each field there. Fitting a stand-in against outputs plus local responses converges with far fewer examples than outputs alone, so a year of ordinary business traffic is a credible training set for a functional copy. They also get the commercially sensitive part directly — the ranked drivers of referral, without any modelling at all. What stays out of reach: the parameters and architecture; behaviour on claim types they never submit, since their coverage is their own book; and any guarantee that a locally read direction holds far from the records it was read at. A copy is also not a flipped decision — most claim fields are attested facts, not free variables. And you cannot separate collection from use in the logs, because every one of those calls was contractually legitimate.

code

text · 9 lines
text
claim_ref: ...
fields_submitted: 47
referral_score: 0.81
contributions (signed, all 47 fields, 6 dp):
  prior_claims_count      +0.243100
  reported_loss_band      +0.118400
  broker_tenure_years     -0.061200
  ...  (44 more)
note: identical per-call price with or without contributions

go deeper

for a junior

Know that a stored history of predictions plus explanations is a training set someone else can fit a similar model on.

for a middle

Explain why attaching a per-field response row to each example is a stronger constraint than the output alone, so fewer examples are needed to reach the same agreement.

for a senior

Bound the claim in an actual write-up: name the segment the copy covers, say what parameters were not recovered, and state that per-call detection is not available because the calls were legitimate.

for a principal

Decide what this finding changes commercially — the ranked driver list may be the real loss, and the response is a disclosure-scope decision rather than an incident.

## What is actually in the archive For each submitted claim over a year: the claim fields the broker sent, the referral score that came back, and a per-feature contribution list saying which fields pushed the score up, which down, and roughly how much. Three columns, not two. That third column is what makes this different from an ordinary log of predictions. ## What it buys **1. A functional stand-in, cheaply.** Fitting a substitute model against outputs alone is a familiar exercise: each reply is one labelled example. With a sensitivity row attached, each reply also constrains *how the stand-in must respond* around that point, not merely what it must output there. That is a stronger constraint per example, so the number of examples needed to reach a given agreement with the target drops. A year of ordinary broker traffic — traffic the operator was paid for — is then a plausible training set. Note the shape of what results: a **functional** copy that agrees with the target where the data lived. Not the parameters. **2. The policy map, with no modelling at all.** Aggregating contribution rankings across thousands of claims yields a statement of which fields drive referral in this insurer's model, and in which direction. For a competitor that is directly usable commercial intelligence, entirely separate from any copy or attack. This is often the largest real loss and the one least discussed. **3. A search direction, per record.** Where the model is fragile near a claim is stated rather than inferred, which is the input to any later attempt to influence outcomes. ## What it does not buy — and being precise here is the senior skill - **Parameters and architecture.** Agreement in behaviour is not recovery of weights. Nothing in an attribution list identifies the model family, its size, or its coefficients. - **Anything outside their book.** A broker writing small commercial property risks submits small commercial property claims. The archive covers that region of the input space and nowhere else, so the stand-in is a copy *of a slice*. Claim types they never wrote are untouched, and there is no cheap way for them to obtain such claims. - **A guarantee off the sampled points.** Sensitivity is local. Reading a direction at a record says how the model responds *there*; extrapolating that far away is exactly where these estimates stop holding. - **A flipped decision.** A referral is a business outcome, and most claim fields are attested facts — incident date, policy number, reported loss — not free variables the broker may set. Knowing which direction would help is a long way from being able to move in it, and moving in it on a real claim is misrepresentation with its own consequences. ## The detection question Asked "can you find this in the logs", the honest answer is that per-call detection is hopeless: every call was a legitimate contracted request with an attribution the contract entitles them to. The tells are distributional and weak: - near-duplicate submissions differing in one field - field-value coverage that does not match the broker's actual book - explained calls with no downstream business action — quoted, scored, never bound - call-volume patterns decoupled from the broker's underwriting seasonality Each of those has innocent explanations. Treat them as prompts for a conversation, not as evidence. ## How to report this finding The temptation is to write it up as "model theft" and the risk of that is that it is dismissed when the copy turns out to be partial. The defensible framing has three parts: 1. **What the disclosure is.** Every integrator holds a per-record description of model response, by contract, for a year. 2. **What that supports.** A functional stand-in over the segments they trade in, plus a direct read of the referral policy's drivers. 3. **What it does not support.** Parameter recovery, coverage beyond their book, or a changed decision on any real claim. That framing survives contact with a sceptical reader, and it puts the decision where it belongs — on how wide and how precise the disclosure needs to be, and to whom.

  • Does the archive help them evade the model as well as copy it?
    It hands them a search direction, which is the first ingredient. It does not hand them the ability to move: most claim fields are attested facts rather than free variables, the direction is local and degrades away from the record it was read at, and altering a real claim to chase it is misrepresentation. Report it as a direction obtained for free, not as a decision flipped.
  • How much of the model do they actually have if the stand-in agrees 95% of the time on their traffic?
    They have a copy of the slice their traffic covers, measured on that same traffic. Agreement on the distribution you sampled says nothing about behaviour off it, and their book is a narrow slice of the insurer's overall exposure. Quote the agreement figure with the segment it was measured on or it means very little.
  • Can you tell collection from ordinary business use in the access logs?
    Not per call — every request was legitimate and the attribution was contractual. The only signals are distributional: near-duplicate submissions, field coverage that does not match their book, scored claims with no downstream business action. All have innocent explanations, so they justify a conversation, not an accusation.

saying these in an interview costs you the question

  • Calls a functional stand-in parameter recovery
  • Claims a copy on their own traffic generalises to all claim types
  • Expects per-call log signals to distinguish collection from use
  • Ignores that ranked drivers alone are commercial intelligence
  • Treats a read search direction as an already-flipped decision

context