IT Guide to TeamAssurance
This article is for System Administators, internal IT and Security Teams.
Overview
TeamAssurance helps organisations worldwide transform their operations to engage employees, get business done faster, and compete more effectively. TeamAssurance empowers departments across your organisation to increase operational efficiency, reduce injuries, improve quality, and drive productivity.
- TeamAssurance is both the name of the company and the cloud-product
- TeamAssurance is a cloud SaaS application, hosted on AWS (Sydney/Australia region), and accessed via a web-browser
- User provisioning is managed by a TeamAssurance Admin, which is a person(s) nominated within your company. SSO user provisioning is also an option.
Settings, policies and recommendations
Whitelisting
To ensure that everyone can access TeamAssurance, the following URLs should be whitelisted and accessible on your network. This includes Firewall and Proxy Server Settings, and other technologies like zscaler (this article may help: https://help.zscaler.com/zia/exempting-urls-cloud-apps-authentication ).
- https://*.teamassurance.com
- https://cognito-idp.ap-southeast-2.amazonaws.com (AWS authentication)
- https://cognito-identity.ap-southeast-2.amazonaws.com (AWS authentication)
- http://s3-ap-southeast-2.amazonaws.com/ta-prod.attachments.teamassurance.com (media attachments)
- https://*.eesel.ai (AI chatbot trained on Help articles and blog posts. No customer data.)
Note: the * denotes a wildcard, which means it can be any text.
Email domains
It is recommended that your email systems whitelist to allow the *@teamassurance.com domain. Examples of email notifications are; password resets, task is assigned, support response etc.
Login options
- Single Sign On (SSO). We recommend enabling SSO to streamline your team's login process and reduce password fatigue, while ensuring that your organization's required Multi-Factor Authentication (MFA) protocols are seamlessly enforced. SSO requires each user to have an email address. This can also be set-up with User Provisioning.
- Username & Password. This is the fall-back default. Does not require an email address. Username is a fixed format that cannot be altered (first name initial + last name). The standard password rule is a 6 character minimum, however this can be configured to a higher minimum. In addition, complexity rules are available for number of lowercase, uppercase, numeric and special characters.
Additionally, a ‘Face Login’ is available. Face Login utilises a device’s camera to recognise a user’s face and log the user in. This can be useful for shared devices, such as tablets, and can be used in addition to the above login options. Facial recognition technology is not as secure as the other options, so please consider this carefully before requesting it. We will require the request in writing.
IP address restriction
Upon request, manual login to the system for your organisation can be restricted to a set of IP addresses/CIDR ranges. SSO logins have access to the system regardless of IP address. This allows you to use SSO for employees that already have a license for your SSO product (e.g. Microsoft ActiveDirectory) but still allow other employees to use the system from inside your network.
Wifi and 4G
The primary modes of data input are tablets and mobile devices. We recommend testing WiFi coverage in all areas of the site where users will access the application. Where Wifi is not practical, consider a SIM card for the devices.
Browsers
We offer support for the immediate and preceding desktop versions of Chrome (recommended), Microsoft Edge and Safari. Other web browsers may work with TeamAssurance, however users could experience issues.
Mobile OS
We offer support for the immediate and preceding versions of iOS and Android operating systems. Older versions of these operating systems may work with TeamAssurance, however users could experience issues.
On mobile devices, TeamAssurance is accessed via a web browser and can be saved as a PWA (Progressive Web Application). The PWA version sits as an icon on the phone screen and behaves similar to native app.
Note that TeamAssurance is not available as an app in the iOS App Store or Google Play store (i.e. no app downloads are required or offered).
API, PowerBI & Reporting
Data from TeamAssurance is available for reports. A Reporting API is available, or a more streamlined Azure storage solution for those in the Microsoft ecosystem. Both will help to point to Power BI reports, which can be iframed back into TeamAssurance.
Hardware
Frontline teams: A tablet per team (or one shared between approx. 10-20 people) is often enough.
Desk-based personnel: Laptop/Desktops with standard Windows and Macs with the latest (or one version previous) operating system.
Tier meeting areas: We strongly recommend a large touchscreen for the main tiered meeting area (55" - 75”). It is also useful to have smaller touchscreens in other meeting areas (32" in portrait orientation).