Terms of Service · Supplement
OWCOL SSO
Authentik by OWCOL — OWCOL SSO — is the identity provider that stands in front of every other OWCOL service. This supplement covers credentials, sessions, and what happens when access is lost.
01Scope
This supplement applies to Authentik by OWCOL, reachable at sso.owcol.com. It sits on top of the OWCOL General Terms and the OWCOL Privacy Policy, both of which apply in full. Where this supplement and the General Terms conflict, this supplement controls — for this service only.
02What this service is
OWCOL SSO is a self-hosted deployment of authentik at sso.owcol.com. It holds your OWCOL identity and issues the sign-in sessions and tokens that let you into Canvas, OWCOL Office, OWCOL Mail, OWCOL SIS, and any other connected application.
It is infrastructure rather than a destination: for most people the only visible part is the sign-in screen and the account settings page.
03Access and accounts
Your OWCOL SSO account is the single key to the rest of the platform. It is provisioned by the administrator and cannot be self-registered.
- Multi-factor authentication may be required for some or all accounts. Where it is offered, enable it.
- Store your recovery codes somewhere safe and offline. They are the fallback when a second factor is lost.
- Sessions expire. Long-lived sessions on shared or public devices are your responsibility — sign out.
- Application passwords and API tokens issued through SSO carry your privileges. Treat them like passwords, scope them narrowly, and revoke ones you no longer use.
If you lose access
Losing your SSO credentials and your recovery codes means losing access to every service behind them, including your mailbox and files. Recovery requires identity verification by the administrator and is not guaranteed to be fast. Email admin@owcol.com.
04Service-specific rules
In addition to the acceptable-use rules in the General Terms, when using OWCOL SSO you agree not to:
- Share your credentials, second factor, recovery codes, or tokens with anyone — including people you trust and including OWCOL staff. No administrator will ever ask for them.
- Sign in on behalf of another person, or let another person use your session.
- Automate sign-in in a way that stores your password in plaintext, or that hammers the login endpoint. Use an application password or an OAuth/OIDC flow instead.
- Connect an unapproved third-party application to your OWCOL identity, or attempt to register an OAuth/SAML client without authorization.
- Probe, enumerate, or brute-force accounts, flows, or endpoints. Authentication systems are monitored, and failed attempts are logged and rate limited.
- Attempt to escalate your own privileges or modify group membership, policies, or flows you have not been granted.
05Your data here
OWCOL SSO stores your username, email address, display name, group memberships, credential material (passwords are stored only as salted hashes), enrolled second factors, and a log of authentication events including timestamps, IP addresses, and user agents.
Authentication logs are security records. They are retained as described in the Privacy Policy and are not deleted on request while they are needed to investigate abuse or meet a legal obligation.
When you sign in to a connected application, OWCOL SSO releases a limited set of attributes — typically your identifier, name, email, and groups — to that application so it can create your session.
06Availability and maintenance
OWCOL SSO is provided on the same reasonable-effort, no-SLA basis as every other OWCOL service. See Availability and changes in the General Terms.
Because SSO gates everything else, an SSO outage is effectively a platform-wide outage. Maintenance on the identity provider is kept short and is normally performed off-hours, but no window is guaranteed and no uptime is promised.
The administrator may terminate active sessions, force a password reset, or require re-enrollment of a second factor at any time for security reasons.
07Ending your use
Closing your OWCOL SSO account closes your access to every connected service. Data held in those services is then handled under each service's supplement and the Privacy Policy. Request closure at admin@owcol.com.
OWCOL may suspend or terminate access to OWCOL SSO under section 9 of the General Terms.
08Upstream software
Authentik by OWCOL is an independently operated deployment of authentik, an open-source project. OWCOL is not affiliated with, endorsed by, or sponsored by Authentik Security, Inc., and Authentik Security, Inc. provides no support or warranty for this deployment. All trademarks belong to their respective owners.
Upstream updates may change or remove features without notice from OWCOL.