Security and data
Workforce access should follow responsibility.
Owlly is designed around organisations, locations, roles and workforce functions so access can be scoped to the work a user is responsible for.
Safe public statements
- Owlly uses authenticated access for product users.
- Product access can be organised around roles and responsibilities.
- Workforce data can be scoped by organisation and location structures.
- Integration access and data exchange are defined during implementation.
- Sensitive workforce data should not be displayed in public product mock-ups or analytics.
- Access, retention and integration requirements should be documented for each deployment.
Security review topics
During a customer review, cover:
- identity and authentication
- user provisioning and removal
- roles and permissions
- organisation and location scoping
- data import and export
- integration authentication
- audit and change records where applicable
- data retention
- incident communication
- subprocessor and hosting information
- privacy and legal requirements