EOI Exchange

Pillar two · Connectivity

Enrollment breaks because every system holds a partial version of the truth.

The carrier system, the ben admin, the HRIS, the payroll system, and the enrollment vendor each see one piece of the worker's election. The worker pays for that fragmentation in coverage gaps and payroll errors. This page is written for Ben Admin and HRIS leaders; carriers and platform engineering teams read the same mechanism.

The belief

When EOI breaks, the intent dies on your platform.

When the worker clicks Complete EOI and lands on a confusing form, a broken link, or a three-week paper delay, that conversion does not go to the carrier. It dies inside the enrollment system. The fix is connectivity that lets each system keep its job and still talk to the others. EOIX is the connective tissue between them.

EOIX integrates by API into ben admin and HRIS systems at the two points where EOI matters. The point where it gets triggered (the cart election crosses GI), and the point where the decision gets written back (the approved coverage lands in the cart for payroll to calculate on). The integration is white-labeled. The Ben Admin keeps the experience. The carrier keeps the rules. EOIX runs the underwriting moment.

Identity is handled by the parent platform wherever possible. Where SSO (Single Sign-On) is available, the EOI app trusts the identity the parent system already verified. Where SSO is not available, a secure token plus identity verification covers the path, including the spouse path that has no parent login.

The architecture is built. Platform partner API connectivity is documented. Alignment work with the platform partner is in progress. The first wave of carrier conversations is underway with multiple Tier-1 group carriers. EOIX is pre-revenue and post-architecture.

The connectivity ecosystem

Six layers. One orchestration.

EOIX orchestrates across the systems that today work in isolation. Each layer keeps its job. EOIX makes the parts talk to each other.

  • HRIS Platforms

    HRIS platforms, employer-of-record systems, and other systems of record for the employee. EOIX reads the identity, eligibility, and demographic context the rules require. White-labeled. No UI rebuild.

  • Enrollment Systems

    Ben Admin (Benefits Administration platform) shopping carts where the elections happen. EOIX triggers when an election crosses the GI (Guaranteed Issue) threshold, returns the decision to the cart, and lets the platform keep ownership of the experience.

  • Carrier Systems

    Carrier policy administration, billing, and post-issue downstream systems. EOIX writes the approved coverage back so the carrier's book of record stays in sync the moment a decision lands.

  • Underwriting Engines

    The underwriting engine executes the carrier's configured rules. EOIX sits in front, runs the adaptive interview, hands the engine what it needs, and returns the decision to the rest of the workflow.

  • Data Sources

    Driving history, prior application history, and prescription history. Pulled in real time inside the decision flow only when the carrier's rules call for them.

  • Workflow Processes

    Identity verification, secure token handoffs, write-back acknowledgments, exception flagging, and governance event logging. Each event lands in the EOIX portal so every party can see the pipeline.

URL hygiene

Carrier-branded. Case-specific. No sensitive data in URLs.

Every launch link is branded for the carrier the employee is buying coverage from. Every link is scoped to a single case. The token in the URL is opaque, and sensitive data (date of birth, SSN, coverage amount) is never carried in the URL itself. It lives behind verification, not behind a query string.

Preferred public URL pattern

https://eoi.carrier.com/launch

The subdomain belongs to the carrier. The path varies per launch option. The token, when present, is opaque.

Identity formats supported

  • SAMLSecurity Assertion Markup Language

    Legacy enterprise SSO format. Widely supported by employer identity providers.

  • OIDCOpenID Connect

    Modern SSO standard layered on OAuth 2.0. Default for newer HRIS and ben admin platforms.

  • JWTSigned JSON Web Token

    Token-based identity claim used for secure deep-links into the EOI app from anywhere.

SSO is the cleanest experience. Where the parent platform supports it, EOIX uses it. Where it does not, secure token plus identity verification covers the path, including spouse links and admin one-off resends.

The boundary

What EOIX does, and what it deliberately does not.

EOIX does not replace the Ben Admin. The Ben Admin keeps the cart, the employee experience, and the payroll handoff. EOIX runs the underwriting moment between them.

Next step

Open a connectivity inquiry.

One conversation with your integration lead. We map the trigger points in your enrollment flow, the identity providers you already use, and the write-back path back into your cart. No platform-wide rollout, no engineering surprises.