Effective governance in OWL combines OWL Compliance controls, Retention Policies, and module and feature access. Together, they help protect sensitive information, apply required handling rules, manage records through their full lifecycle, and ensure users have access only to the modules and actions needed for their responsibilities.
Although they work together, they address different questions: OWL Compliance determines how a record is protected and handled; a Retention Policy determines how long the record is kept and when it is archived or disposed of; and module and feature access determines which users can access a module or perform a specific action.
OWL Compliance and Retention Policies
| Governance area | OWL Compliance | Retention Policies |
|---|---|---|
| Primary purpose | Applies regulatory, classification, access, and handling controls to sensitive records. | Defines how long a record must be retained and what happens when its retention dates are reached. |
| Focus | Record protection, access control, regulatory requirements, and compliance reviews. | Record lifecycle management, including archive, Trash, and permanent deletion. |
| Examples | Juvenile Compliance, 28 CFR Part 23 Compliance, data classification and access rights, and Legal Hold. | Retention periods appropriate to the record type and applicable organization, legal, or regulatory requirements. |
Best practices for OWL Compliance
- Configure only the compliance features that apply to the organization’s jurisdiction, regulatory obligations, and operating policies.
- Use Juvenile Compliance and appropriate access restrictions for records involving juvenile subjects.
- If your organization uses 28 CFR Part 23 Compliance, define and document how authorized users must create, review, access, share, retain, and dispose of applicable criminal intelligence records.
- Apply a Legal Hold promptly when a record may be relevant to litigation, an audit, a regulatory inquiry, or an investigation.
- Apply data classifications and access rights consistently so sensitive records are available only to authorized users.
- Review compliance assignments and access restrictions regularly to confirm they remain appropriate.
- Use OWL’s audit history to review compliance-related actions, including changes to classifications, access rights, Legal Holds, and record lifecycle status.
Best practices for Retention Policies
- Create retention policies based on record type and the organization’s approved retention schedule. Avoid applying one policy to all records unless that approach is formally required.
- Define archive and delete dates that meet applicable organization, legal, and regulatory requirements.
- Assign the appropriate policy when the record is created, so it is governed throughout its lifecycle.
- Periodically identify records without an assigned retention policy and resolve any gaps.
- All records not assigned a retention policy can be viewed within the Administration module.
- All records not assigned a retention policy can be viewed within the Administration module.
- Review retention policies whenever laws, regulations, contracts, or internal retention requirements change.
- Confirm the OWL Compliance setting for linked records. A linked record can either follow the parent record’s compliance and retention policy or retain its own compliance and retention policy.
- Do not use a policy change to reduce a required retention period or delete a record earlier than permitted.
Best practices for module and feature access
Module and feature access is an important governance control. Apply the principle of least privilege: each user should have only the access needed to perform their assigned responsibilities.
- Start with role-based access to create a consistent access baseline for users with similar responsibilities.
- Use user-level access changes only when a specific user needs an approved exception to their role-based access. Review these exceptions regularly and remove access that is no longer required.
- Restrict high-risk actions, including deleting records, changing access rights, assigning retention policies, and applying or releasing Legal Holds.
- Review external collaborator access before sharing records, particularly where records contain sensitive, restricted, or juvenile information.
- When a user changes roles or departments, review their module and feature access to remove permissions that are no longer needed.
- Confirm that access assignments remain within the organization’s licensed OWL edition and enabled modules.
Using the controls together
Use OWL Compliance and Retention Policies as complementary controls:
- Apply Compliance Policies to determine how a record is protected, who can access it, and what regulatory controls apply.
- Apply Retention Policies to determine how long the record is kept, when it should be reviewed, archived, or deleted.
- Apply a Legal Hold when required. A Legal Hold prevents the record from being archived, deleted, or permanently disposed of through the retention lifecycle until the hold is released.
- Periodically review compliance assignments, access restrictions, Legal Holds, and retention policies.
- Review module and feature access, especially user-specific exceptions and high-risk permissions.
- Use audit history to confirm that compliance, access, and lifecycle actions were performed as expected.
- Document governance policies and train administrators to consistently classify records and assign appropriate retention policies during record creation.
Example governance workflow
- A user creates or uploads a record that contains sensitive information.
- An authorized user applies the appropriate OWL Compliance controls, such as a classification, access restriction, or juvenile handling requirement.
- The appropriate Retention Policy is assigned based on the record type and approved retention schedule.
- If the record becomes relevant to litigation, an audit, or an investigation, an authorized user applies a Legal Hold.
- After the Legal Hold is released, the record continues through its retention lifecycle. It is archived or moved to Trash when its policy dates are reached, subject to all applicable governance controls.
Administration checklist
- Maintain written organization policies for classification, access, retention, Legal Hold, and record disposal.
- Give users only the permissions needed for their responsibilities.
- Establish a role-based access model and document approved individual access exceptions.
- Train users to classify records correctly and assign the appropriate retention policy at creation.
- Review audit history regularly for sensitive records and administrative changes.
- Reassess governance configuration after regulatory, organizational, or system changes.