Skip to main content

General policies

Recommended general best-practice policies for you to communicate to all users:

  • Do not store personal/non-work credentials and other secrets in Bravura Safe. Bravura Safe is a corporate application, and your account is subject to termination without notice. Store only work-related items.

  • Set up your Emergency contacts as soon as possible after logging in for the first time.

  • Set up your preferred method for alternative two-step login.

Emergency access

Create and communicate emergency access business policies:

  • How many emergency contacts do users need?

  • How many days should “Wait Time” be? Often users set this to 1, 2 or 7 days so that there is time to reject the access request, but not so much time that it impacts business workflow.

  • Who do they need to assign? (Direct manager/supervisor, HR, peer...etc)

    The use case for emergency access is when an employee goes on vacation or leave and a colleague requires access to items stored within their safe. The employee’s allocated emergency access colleagues are given the ability to request access to the employee’s safe. Once requested and approved, the colleague can use items stored in the employee’s safe immediately. If the employee does not respond to the request, access is granted after the emergency access time limit elapses (Anywhere from 1-90 days). Watch the Emergency Access video below for more options.

    In a true emergency or in event of employee termination, a master password reset would be requested.

Two-step login methods

Inform users of the ability to change their two-step login methods.

  • When Bravura OneAuth is implemented as the secondary authentication method, the “two-step login” setting only affects the backup authentication method provided. This would be used if the user’s mobile device is inaccessible.

  • If Bravura OneAuth is not used, the default two-step login method is Email PIN. In this case, it may be desired to inform users of their ability add an authenticator app as a personal two-step login method.

In either scenario, it is advised that users continue to keep Email PIN as one of the backup methods. Authenticator app can still be added as an option, but if it is the only option, they risk locking themselves out of their account if their mobile device is inaccessible.