Identity and device
Subject identifiers, device identity, enrollment, ownership, posture observations, evidence source, freshness, and reason codes used for policy.
PRIVACY AND DATA HANDLING
Oten Access separates identity, device, policy, enforcement, session, operational telemetry, and security evidence so each category can have a defined purpose, access boundary, retention rule, and deletion path.
System role: Privacy owner + Security owner + Customer data owner
Evaluation depends on: Requires an approved privacy notice, deployment data-flow inventory, retention schedule, regional scope, and subprocessor record.
Subject identifiers, device identity, enrollment, ownership, posture observations, evidence source, freshness, and reason codes used for policy.
Policy identifiers and versions, decision inputs, reason codes, targeted enforcement points, acknowledgement, partial failure, and recovery state.
Resource, protocol, path mode, session identifiers, timing, and supported session evidence, without treating payload inspection as the default.
Service health, version, capacity, failure, rollout, and diagnostic data kept separate from user-content and security-investigation evidence.
Findings and bounded supporting evidence with purpose-based access, minimization, masking, retention, export, and review controls.
Business contact details and high-level evaluation context. Requests must exclude passwords, secrets, personal data, internal IPs, hostnames, and sensitive network diagrams.
The form collects a name, work email, organization, role, evaluation topic, and high-level problem description only after consent. Delivery is enabled only when an approved destination, server-side credential, and privacy notice are configured together.
Next in Oten Access
Map each data category to purpose, ownership, access, region, retention, deletion, and incident responsibility.