OWL provides multiple security controls to protect user accounts, sensitive records, and organizational data. Users and administrators should follow these recommended practices to maintain secure access to the OWL platform.
Authentication
OWL supports the following authentication methods:
- Username and password
- Okta-backed Single Sign-On (SSO)
When your organization has SSO configured, use SSO whenever possible. SSO allows your organization to centrally manage user identities, authentication policies, and account access.
Users should:
- Keep their OWL password confidential.
- Use a strong and unique password.
- Never share login credentials with another user.
- Sign out when using a shared or public device.
- Report unexpected login activity to an administrator.
Multi-Factor Authentication
Multi-Factor Authentication, or MFA, provides an additional layer of account protection.
MFA can be configured at the following levels:
- Organization
- Role
- Individual user
Administrators can configure up to two authentication factors.
Primary authentication options
- Security Questions
- Time-based One-Time Password (TOTP)
- Facial Recognition
Secondary authentication option
- IP Address Restriction
When MFA is enabled, users must complete the required verification process before accessing OWL.
Users should keep their registered authentication method secure and immediately notify an administrator if they lose access to their authentication device or suspect that their account has been compromised.
Access Control and Permissions
OWL uses role-based permission access control. Each user should be assigned only the license, role, department, and permissions required to perform their responsibilities.
Common OWL roles may include:
- Administrator
- Supervisor
- User
- Information Sharing User
- External Collaborator
Users should not attempt to access records or functionality outside their assigned responsibilities.
Administrators should regularly review:
- Active user accounts
- Assigned roles
- License types
- Department assignments
- User permissions
- Inactive or closed accounts
Access should be updated or revoked when a user changes responsibilities, transfers departments, leaves the organization, or no longer requires access.
Case and Record Visibility
Access to OWL cases and records is controlled by the user’s role, department, record ownership, assignment, and collaboration permissions.
Users are not automatically granted global visibility into all cases. Access must be provided through the appropriate ownership, assignment, permission, or collaboration process.
Users should:
- Access only records required for authorized business purposes.
- Avoid sharing case information outside approved OWL workflows.
- Confirm that the correct users and departments are selected before sharing information.
- Report unexpected access to restricted records.
External Collaborator Security
External collaborators must be individually approved before they can access shared information.
Depending on the organization’s configuration, approval may be completed by a case owner, supervisor, or authorized administrator.
External collaborators should receive access only to the specific cases, tasks, documents, subjects, or evidence required for their work.
Access may be configured as:
- Read-only
- Read/write
External collaborators must not be given access to unrelated cases, records, investigations, or organizational data.
Collaboration access should be reviewed regularly and modified or revoked when:
- The assigned work is completed.
- The collaboration period expires.
- The external user no longer requires access.
- The vendor or partner relationship ends.
- A security concern is identified.
Following Organizational Compliance Policies
Users must access, search, share, download, retain, and distribute information only for authorized business purposes and in accordance with their organization’s applicable compliance, retention, and data-governance policies.
Protecting Sensitive Information
Users should follow these practices when handling sensitive information in OWL:
- Upload documents only to the correct case, subject, task, or record.
- Review recipients before sharing information.
- Only download sensitive information to unauthorized devices.
- Only send OWL data through unapproved email or file-sharing systems.
- Avoid including unnecessary personal or confidential information in notes.
- Follow organizational policies for printing, exporting, and disseminating records.
- Immediately report accidental disclosure or incorrect record access.
Session and Device Security
To protect active OWL sessions:
- Lock your device when stepping away.
- Do not leave OWL open on an unattended device.
- Use only approved devices and secure networks.
- Avoid accessing OWL through public or unsecured Wi-Fi.
- Keep browsers, operating systems, and security software updated.
- Do not save passwords in an unapproved browser or password manager.
OWL may automatically end inactive sessions according to the organization’s configured session-timeout policy.
Reporting a Security Concern
Contact your OWL Administrator or organizational security team immediately if you:
- Suspect unauthorized account access.
- Receive an unexpected MFA request.
- Accidentally share information with the wrong user.
- Notice access to a case or record you should not be able to view.
- Lose a device used to access OWL.
- Believe that your password or authentication method has been compromised.
Prompt reporting allows administrators to review account activity, revoke access, reset authentication settings, and take other appropriate security actions.