# Client oversight — the bank window, which ships as Glass

> Glass is Otto's client oversight view: a placing bank signs in and reads its own portfolio, compliance posture and audit trail in the firm's own live record.

- Source: https://ottoforfirms.com/platform/bank-window/
- Publisher: Otto — https://ottoforfirms.com
- Updated: 2026-07-26
- Status: in attorney review. Served noindex and excluded from the sitemap; do not cite as settled.

**In review — not indexed.** This page describes what Otto does and is readable in full. It stays out of search until it has been reviewed, because a product claim about a compliance control is a claim somebody will hold us to.

[The Otto platform](https://ottoforfirms.com/platform/)

Glass is the read-only view a placing bank signs into to see its own portfolio inside the firm's live record — accounts, compliance posture, attestations and the audit trail — scoped to that client's placements only, with a button to request an audit package. It ships under the name Glass; Bank Window was the earlier name for the same thing.

## Key facts

- The product ships as Glass. Bank Window was the earlier internal name, and the code, the route and the oversight role label were renamed to match the name on the site. If a document says Bank Window, it means this.
- Four tabs: portfolio overview, compliance posture, trust and attestations, and the audit trail.
- Scoped by client. Internal firm notes, other clients' data and attorney work product are not in the view.
- Read-only. A bank cannot act on an account through Glass. It can request an audit package, which creates work on the firm's side and an event on the trail.
- Every figure in the demonstration module — compliance scores, network benchmarks, dispute-resolution averages — is seeded. Otto has no live bank clients, so nothing shown is a measurement across a client base.
- The certification tiles in the demo's attestations tab are synthetic. Otto's SOC 2 Type II and ISO 27001 audits are in progress, not complete.

## Why does this product have two names?

Because it was built under one and sold under another, and for a while both were true at once — the marketing site said Glass while the code, the sidebar route and the oversight role label all said Bank Window. One product with two names is how a client ends up asking which one they bought. The code was renamed to Glass, which is the name on the site. This page carries the old name in its URL because that is the phrase a buyer types, and the answer to the question is that they are the same product.

## What does a bank see in Glass?

Its own placements, listed with account, type, queue and balance, and badged where a hold is on. Above them a live activity strip showing recent events on those accounts as they are written. A posture tab with tiles for call-frequency compliance, dispute response timeliness, documentation completeness, honoured cease and attorney flags, and recording-consent capture, each with a twelve-week trend. A trust tab holding the firm's attestations, insurance, retention schedule and recording-consent posture. And the audit trail itself, filtered to that client's accounts, with a request button on it.

## Is this the same record the firm works from?

Yes, and that is the whole design. The posture numbers are recomputed from case state rather than assembled into a report for the review, and the activity strip is the same event stream the firm's own audit screen reads, filtered by client. The alternative — a package built for the reviewer — tests the firm's assembly process at least as much as its conduct, because the firm chooses what goes in it. TODO: confirm with counsel how this is framed for a bank audience, since it must describe visibility and not imply an oversight conclusion.

## What can a bank not see?

Other clients' accounts, the firm's internal notes, and attorney work product. The scoping is by client identifier on the account, and the view states its own limit on the page rather than leaving the reader to assume it. Read-only means read-only: there is no action in Glass that changes an account. The one thing a bank can start is a request — for an audit package, or for the SOC report — and each request is itself written to the audit trail, so the firm can show what was asked for and when.

## Does this satisfy a vendor oversight programme?

No, and it is not offered as one. Federal guidance on third-party risk expects oversight proportionate to the harm a third party could cause, and consumer debt litigation sits high on that scale — the firm contacts the bank's former customers, files in the bank's name and furnishes to credit bureaus. What Glass changes is the evidence available to an oversight team: continuous rather than sampled, current rather than lagged by a quarter, and assembled by the system rather than by the party being reviewed. Whether that meets a given supervisory expectation is a question for the bank's own counsel and its examiners. TODO: verify the interagency third-party risk guidance reference against the agencies' published text and cite it directly.

## What is built today?

The portal is real and runs against the same store the firm-side application uses, which is what makes the same-record claim demonstrable rather than asserted. The numbers in it are seeded: the compliance score, the network benchmark strings, the dispute-resolution average and the twelve-week sparklines are demonstration values chosen to show the shape of the screen. Treat them as layout, not as evidence. There is no live bank tenant in this build.

---

This page describes Otto, not the law, and is not legal advice. Otto applies rules that have been written down correctly; it does not warrant that using it results in compliance with any statute, regulation or contract. Where a rule is named here, confirm it against the primary source and your own counsel before relying on it.
