Workspace access and agency boundaries
InferOwl uses agency workspaces to organize recruiting records and user access. Protected product requests check the signed-in account and its agency context. Account checks use the current user profile, including whether the account is active, so a previously issued sign-in token alone does not establish continued access.
Owner, manager, and recruiter roles support different responsibilities. The permission model also supports custom roles and individual permission adjustments. Access depends on the action and the permissions configured for the user. Review the exact access your team needs during setup.
Assign responsibility for invitations, role changes, and offboarding. Recheck permissions when someone moves to a different desk or leaves the agency. A useful access review covers both InferOwl and the external accounts connected to it.
Activity history and investigation
The product includes an Audit Log for recorded workspace events. It shows event types, timestamps, and associated details, with search and filtering to help a permitted user find relevant activity. The records can support a review of what happened around a reported issue.
An activity log is not a promise that every possible action is recorded or that records are kept indefinitely. If your agency needs specific events, retention periods, or an export for an audit, identify those requirements during diligence and confirm the available coverage.
Data access, removal, and retention
Recruiting records, account details, communication history, and operational events have different purposes. A request to remove a user account is different from a request to remove candidate records or close an agency workspace. Describe the data involved when requesting an export or deletion.
Contact the team to confirm the appropriate process and permissions for your request. Agree on retention periods, export format, deletion scope, and treatment of linked business records and backups before transferring data with specific lifecycle requirements.
For an initial review, use fictional or redacted records wherever possible. Healthcare staffing examples should use candidate and job information appropriate to the task. Do not include patient records in a product demonstration or ordinary support message.
Connections and data flow
A connection can introduce additional permissions and another provider into a workflow. Start by identifying the source system, the records involved, and the direction in which information needs to move. Confirm who owns the external account and who can approve or revoke access.
Scope each integration with the team. Ask which information leaves the workspace, what the receiving service does with it, and how a failed or interrupted transfer is handled. An integration mentioned during a conversation is not a guarantee that your account, data format, or required sync behavior is supported.
For the marketing website, the Book now calendar is an Orufy embed that loads independently of optional analytics. Our privacy information explains that connection and the visitor controls for Google Analytics.
Human review of AI-assisted work
Recruiters can use candidate and communication evidence to assess AI-assisted work. Review the underlying source, check whether information is current, and investigate missing or conflicting details before a recommendation informs an action.
For your evaluation, define who can review the output, who can act on it, and how corrections will be captured. Include review and correction time in productivity measurements. A useful pilot measures accepted work, with the same quality criteria used for the baseline.
Confirm which data an AI-enabled workflow sends to a provider and which provider terms apply. This overview does not promise a particular model-processing region, retention setting, or training-data exclusion for every deployment.
What to confirm in a security review
Bring the requirements your agency and clients need to satisfy. The review should cover the proposed implementation and the evidence required by your procurement process. Ask for confirmation before depending on a control or contractual commitment.
This page describes product behavior and review topics. It does not assert SOC 2 or ISO 27001 certification, HIPAA compliance, a penetration-test result, or a contractual service level.
- Hosting and processing locations, relevant providers, and data-transfer arrangements.
- Encryption in transit and at rest for the services and data paths in scope, including key-management responsibilities.
- Account authentication requirements, privileged access, role configuration, and offboarding.
- Backup coverage, restore testing, recovery objectives, and retention or deletion arrangements.
- Incident contacts, escalation steps, notification obligations, and agreed response expectations.
- Any certifications or independent assessments your procurement process requires, with their scope and date.
Report a security concern
Email hello@inferowl.com with the subject Security report. Include the affected page or feature, when you observed the issue and your time zone, a short explanation of the impact, and steps that reproduce it using your own account or sample data.
Remove candidate information, passwords, access tokens, and other secrets from screenshots and logs. If sensitive evidence is needed, ask the team for an appropriate transfer method before sending it. Share enough context to identify the issue without including unrelated records.
If you encounter information you should not be able to access, stop at the minimum observation needed to report it. Do not download additional records, change other users’ data, or disrupt service. This reporting route does not grant permission to conduct intrusive testing.