User roles and permissions
Public documented controlEvidence available
The onCourse handbook documents individual users, roles and permissions.
Open sourceWhat to review
Map access to responsibilities and test least-privilege settings.
Assurance and evidence
Bring your security, privacy and IT questions into one conversation. Start with the public documentation below, then work with us to confirm the evidence and service arrangements your organisation needs.
Index reviewed 5 October 2026
The onCourse handbook documents individual users, roles and permissions.
Open sourceMap access to responsibilities and test least-privilege settings.
The handbook documents security settings and two-factor authentication for onCourse logins.
Open sourceConfirm the login and identity design for the proposed users, including any separately scoped SSO.
The handbook documents audit logging for reviewing who changed a record and when.
Open sourceConfirm relevant events, retention, access and investigation needs.
ISH publishes a payment-security attestation for review. Its applicability depends on the payment flow and service boundary.
Open sourceReview the current document, providers, responsibilities and proposed payment flow. Do not treat it as a blanket certification claim.
ISH describes onCourse as operated on AWS with Australian data storage for the managed service context described on this site.
Open sourceConfirm data categories, flows, backups, subprocessors and any connected systems. This is not a claim that every connected copy of data remains in Australia.
Current recovery evidence and service commitments are reviewed for the proposed arrangement rather than asserted publicly here.
Request the applicable recovery approach, service commitments, escalation path and evidence.
Accessibility requirements and any cross-institution identity or consolidated reporting need validation against the intended scope.
Agree standards, test scenarios, responsibilities, data boundaries and acceptance evidence.