owlly

Security and data

Workforce access should follow responsibility.

Owlly is designed around organisations, locations, roles and workforce functions so access can be scoped to the work a user is responsible for.

Safe public statements

  • Owlly uses authenticated access for product users.
  • Product access can be organised around roles and responsibilities.
  • Workforce data can be scoped by organisation and location structures.
  • Integration access and data exchange are defined during implementation.
  • Sensitive workforce data should not be displayed in public product mock-ups or analytics.
  • Access, retention and integration requirements should be documented for each deployment.

Security review topics

During a customer review, cover:
  • identity and authentication
  • user provisioning and removal
  • roles and permissions
  • organisation and location scoping
  • data import and export
  • integration authentication
  • audit and change records where applicable
  • data retention
  • incident communication
  • subprocessor and hosting information
  • privacy and legal requirements

Related

Need a security or data review?