Named accounts and MFA
Live agency users sign in with individual accounts and multi-factor authentication. Administrators can see enrollment status, require setup, reset MFA, and sign out active sessions.
CJIS area: Identification and Authentication
Security and CJIS controls
Citation Platform is designed around the FBI CJIS Security Policy control areas that apply when systems process, store, or transmit Criminal Justice Information. Here is what the platform uses and what agencies can expect to manage.
Inside Citation Platform
These controls work together. Authentication confirms the user, device approval confirms the endpoint, permissions limit access, encryption protects the data, and audit history records important activity.
Live agency users sign in with individual accounts and multi-factor authentication. Administrators can see enrollment status, require setup, reset MFA, and sign out active sessions.
CJIS area: Identification and Authentication
Officer, Agency Administrator, Court Clerk, Read-Only Auditor, and Platform Owner roles receive different tools and data access. Permissions follow job responsibility and least privilege.
CJIS area: Access Control
A new browser or device must be registered and approved before it can receive protected agency information. Until approval and key provisioning are complete, citation records, audit details, and print jobs remain unavailable.
CJIS areas: Access Control and Authentication
Protected data uses encrypted connections and encrypted storage. The Agency Data Gateway controls key provisioning for approved endpoints so protected agency records are not opened to every signed-in device.
CJIS area: System and Communications Protection
Authentication events, security and administrative actions, citation lifecycle changes, voids, amendments, and version history are recorded for authorized review.
CJIS area: Audit and Accountability
Authorized administrators can disable users, end sessions, and manage agency states without erasing accountability. Production records are preserved through suspension, archival, correction, and recovery workflows.
CJIS areas: Access Control and Contingency Planning
CJIS control lifecycle
FBI CJIS Security Policy v6.1 addresses the complete lifecycle of CJI. Citation Platform is designed so an agency can evaluate the product across the same major operational areas.
Named users, MFA, approved devices, session controls, role separation, and least privilege.
Reviewable security events, administrative actions, citation history, and authorized changes.
Controlled changes, maintained software, secure settings, and visibility into operational state.
Agency data storage choices, backups, recovery planning, retained history, and service restoration.
Defined reporting, containment, recovery, and coordination responsibilities for security events.
The platform, agency, devices, network, personnel, training, agreements, and local procedures all contribute to the final security posture.
Policy reference: FBI Criminal Justice Information Services Security Policy, Version 6.1, June 25, 2026.
Agency administration
Agency leaders should not have to guess which users are protected, which devices are approved, or whether access has been shut down. Citation Platform brings those tasks into the administrative workflow.
Review user enrollment, require MFA at the next login, reset an enrollment when appropriate, and end active sessions.
Review a new endpoint before allowing it to receive protected records or agency-controlled key material.
Create users within agency limits and assign only the role needed for officer, administrator, court, or audit responsibilities.
Manage agency access without treating production history like disposable test data. Reset tools remain limited to demo or training environments.
Use audit information to understand important account, device, administrative, and citation events.
Direct answers
The device can be identified and registered, but protected citation records, audit details, and print jobs remain unavailable until an Agency Administrator approves it and the Agency Data Gateway provisions the required key.
Live agency environments are designed to require MFA. Demo or training environments may be configured differently so agencies can evaluate workflow without confusing test access with production access.
Agencies choose and control their production system of record, such as approved SharePoint, OneDrive, or local network storage reached through the Agency Data Gateway. Deployment choices must match agency and CJIS requirements.
The design records authentication and security events, administrative actions, citation creation and issue activity, voids, amendments, and retained versions for authorized review.
No. The FBI publishes the CJIS Security Policy, while agencies and the appropriate CJIS authorities evaluate the full deployment. LevelReach does not claim FBI endorsement or formal government approval.
No. Software controls are one part of the deployment. Agency policies, personnel screening, training, devices, physical safeguards, networks, agreements, incident procedures, and ongoing administration also matter.
Citation Platform is designed to support an agency's CJIS Security Policy obligations. Final compliance depends on the complete agency environment and the requirements of the appropriate CJIS authorities.
Agency security review
Bring your device, identity, storage, court, and operating requirements to a focused Citation Platform discussion.