Security Best Practices for Users

  • Updated

OWL provides multiple security controls to protect user accounts, sensitive records, and organizational data. Users and administrators should follow these recommended practices to maintain secure access to the OWL platform.

Authentication

OWL supports the following authentication methods:

  • Username and password
  • Okta-backed Single Sign-On (SSO)

When your organization has SSO configured, use SSO whenever possible. SSO allows your organization to centrally manage user identities, authentication policies, and account access.

Users should:

  • Keep their OWL password confidential.
  • Use a strong and unique password.
  • Never share login credentials with another user.
  • Sign out when using a shared or public device.
  • Report unexpected login activity to an administrator.

Multi-Factor Authentication

Multi-Factor Authentication, or MFA, provides an additional layer of account protection.

MFA can be configured at the following levels:

  • Organization
  • Role
  • Individual user

Administrators can configure up to two authentication factors.

Primary authentication options

  • Security Questions
  • Time-based One-Time Password (TOTP)
  • Facial Recognition

Secondary authentication option

  • IP Address Restriction

When MFA is enabled, users must complete the required verification process before accessing OWL.

Users should keep their registered authentication method secure and immediately notify an administrator if they lose access to their authentication device or suspect that their account has been compromised.

Access Control and Permissions

OWL uses role-based permission access control. Each user should be assigned only the license, role, department, and permissions required to perform their responsibilities.

Common OWL roles may include:

  • Administrator
  • Supervisor
  • User
  • Information Sharing User
  • External Collaborator

Users should not attempt to access records or functionality outside their assigned responsibilities.

Administrators should regularly review:

  • Active user accounts
  • Assigned roles
  • License types
  • Department assignments
  • User permissions
  • Inactive or closed accounts

Access should be updated or revoked when a user changes responsibilities, transfers departments, leaves the organization, or no longer requires access.

Case and Record Visibility

Access to OWL cases and records is controlled by the user’s role, department, record ownership, assignment, and collaboration permissions.

Users are not automatically granted global visibility into all cases. Access must be provided through the appropriate ownership, assignment, permission, or collaboration process.

Users should:

  • Access only records required for authorized business purposes.
  • Avoid sharing case information outside approved OWL workflows.
  • Confirm that the correct users and departments are selected before sharing information.
  • Report unexpected access to restricted records.

External Collaborator Security

External collaborators must be individually approved before they can access shared information.

Depending on the organization’s configuration, approval may be completed by a case owner, supervisor, or authorized administrator.

External collaborators should receive access only to the specific cases, tasks, documents, subjects, or evidence required for their work.

Access may be configured as:

  • Read-only
  • Read/write

External collaborators must not be given access to unrelated cases, records, investigations, or organizational data.

Collaboration access should be reviewed regularly and modified or revoked when:

  • The assigned work is completed.
  • The collaboration period expires.
  • The external user no longer requires access.
  • The vendor or partner relationship ends.
  • A security concern is identified.

Following Organizational Compliance Policies

Users must access, search, share, download, retain, and distribute information only for authorized business purposes and in accordance with their organization’s applicable compliance, retention, and data-governance policies.

Protecting Sensitive Information

Users should follow these practices when handling sensitive information in OWL:

  • Upload documents only to the correct case, subject, task, or record.
  • Review recipients before sharing information.
  • Only download sensitive information to unauthorized devices.
  • Only send OWL data through unapproved email or file-sharing systems.
  • Avoid including unnecessary personal or confidential information in notes.
  • Follow organizational policies for printing, exporting, and disseminating records.
  • Immediately report accidental disclosure or incorrect record access.

Session and Device Security

To protect active OWL sessions:

  • Lock your device when stepping away.
  • Do not leave OWL open on an unattended device.
  • Use only approved devices and secure networks.
  • Avoid accessing OWL through public or unsecured Wi-Fi.
  • Keep browsers, operating systems, and security software updated.
  • Do not save passwords in an unapproved browser or password manager.

OWL may automatically end inactive sessions according to the organization’s configured session-timeout policy.

Reporting a Security Concern

Contact your OWL Administrator or organizational security team immediately if you:

  • Suspect unauthorized account access.
  • Receive an unexpected MFA request.
  • Accidentally share information with the wrong user.
  • Notice access to a case or record you should not be able to view.
  • Lose a device used to access OWL.
  • Believe that your password or authentication method has been compromised.

Prompt reporting allows administrators to review account activity, revoke access, reset authentication settings, and take other appropriate security actions.