An AI assistant can help the owner of an insurance agency without improving how the team handles requests. It prepares a brief, finds information or drafts a reply when someone asks. Incoming emails, missing documents and deadlines still move through the usual channels.
The case below is a composite, illustrative scenario. It does not describe an identifiable client, constitute a testimonial or claim measured results. It explains the boundary between an OpenClaw assistant and a Hermes agent in a multi-branch agency.
The Starting Point: a Useful Personal Assistant
Imagine an independent insurance agent who runs five branches. The owner uses OpenClaw from a messaging app to prepare meetings, summarize threads and draft replies.
That use remains relevant. The assistant helps one person work within their context. Its value still depends on the requests that person thinks to make. If a certificate request reaches a branch inbox or a claim file remains incomplete, nothing happens until someone prompts the assistant.
Opening the same assistant to every team does not automatically solve the problem. The agency must still define rights by branch, the authoritative source for each piece of information, what may be prepared or sent, and which records must be retained.
When the Need Becomes a Process
In a multi-branch agency, requests may arrive by email, phone, form and in person. They do not carry the same risk:
- a missing-document request can follow an approved template;
- a claim-related draft needs review;
- a question about coverage or a recommendation requires a competent person;
- a complaint or cancellation must follow the agency's procedure;
- a document containing personal data must only reach the right recipient.
French insurance law notably requires a distributor to state the customer's demands and needs in writing and provide objective information that enables an informed decision. In 2024, the ACPR also issued a recommendation on gathering customer information for the duty to advise.
An agent should therefore not improvise a recommendation. A reasonable role is to classify, collect, prepare and route, while rules keep sensitive decisions under human control.
Assistant and Agent: Different Triggers
| Question | AI assistant | AI agent |
|---|---|---|
| Trigger | A user request | A scoped event: email, form, deadline |
| Scope | Research, drafting, summaries | Steps in a defined process |
| Access | The user's context | Explicitly authorized tools and data |
| Record | Conversation history | Log of inputs, actions, approvals and errors |
| Sensitive case | The user decides what to ask | The system blocks or routes according to a rule |
Hermes does not become reliable merely because it acts autonomously. It becomes operable when autonomy is limited to tested, reversible actions and recovery is clear when a rule does not cover the case.
Scoping the Migration
Migration starts with one flow, not by connecting every inbox.
For each request in that flow, document:
- its input channel and minimum required data;
- the responsible person or team;
- the systems of record;
- required checks;
- actions the agent may prepare;
- decisions that remain human;
- retention periods for records.
Assistant history can help identify repeated requests and useful language. It should not be copied wholesale into a new agent. Conversations may contain unnecessary data, assumptions or overly broad access.
Three Levels of Autonomy
Level 1: Classify and Acknowledge
The agent identifies the branch, request type and probable file. It may prepare or send an approved acknowledgment without answering the substance. Any ambiguity about identity, policy or recipient blocks the message.
Level 2: Prepare for Approval
The agent gathers authorized documents, flags missing items and prepares a draft. An employee checks the source and approves the action. Useful human edits become test feedback, not uncontrolled automatic learning.
Level 3: Route Without Acting
Questions involving the duty to advise, complaints, inconsistencies, cancellations and uncovered situations are routed to a person. The agent provides available facts and links to sources. It does not conclude on behalf of the advisor.
This approach follows the principles in the article on human approval for production AI agents.
Protecting Data and Recipients
Sending a document to the wrong recipient is not automatically a reportable breach. It may constitute a personal-data breach when confidentiality, integrity or availability has been compromised. The controller must document the incident and assess risk. Notification to the CNIL is required when the breach is likely to create a risk to people's rights and freedoms.
The workflow should therefore check identity and destination, minimize attachments, log the action and support rapid suspension. Secrets, execution history and backups are part of the security scope.
Measure Before Expanding
Start in preparation mode, with approval for every output. Build a test set containing ordinary, ambiguous and prohibited cases. Then measure:
- classification quality;
- missing documents or context;
- drafts corrected by teams;
- actions correctly blocked;
- recipient or case-file errors;
- recovery time when a tool is unavailable.
There is no universal autonomy threshold. An action should expand only after sufficient results on the agency's corpus and approval from the process owner.
Sources Consulted
- Legifrance, French Insurance Code, Article L521-4, accessed August 13, 2026.
- ACPR, Recommendation 2024-R-03 on collecting customer information, accessed August 13, 2026.
- CNIL, reporting personal-data breaches, accessed August 13, 2026.
Choosing the First Flow
The first flow should be frequent, bounded and verifiable. A document request or inbox classification is usually a better candidate than a recommendation about coverage.
The OpenClaw, Hermes and AI consulting pages compare the approaches and describe how to scope a prototype without claiming to automate the work of an insurance professional.
Also available: Read in French