Commit 80b8f1da authored by Iris Blackburn's avatar Iris Blackburn 🤔
Browse files

Add log request verification steps

parent 48c6dd62
Loading
Loading
Loading
Loading
+6 −3
Changes for content/handbook/support/workflows/account_verification.md: 6 added lines, 3 removed lines.
Original line number Diff line number Diff line
@@ -63,6 +63,8 @@ See the [Enterprise User section](../workflows/gitlab-com_overview.md#enterprise
Before sending challenges, determine whether the ticket was opened by an Enterprise Owner. If so, please use the [`Support::SaaS::GitLab.com::Account Ownership Verification - GitLab.com - Enterprise Owner` macro](https://gitlab.com/gitlab-com/support/zendesk-global/macros/-/blob/master/active/Support/SaaS/GitLab.com/Account%20Ownership%20Verification%20-%20GitLab.com%20Enterprise%20Owner.md?ref_type=heads).
Otherwise, use the [`Support::SaaS::GitLab.com::Account Ownership Verification - GitLab.com` macro](https://gitlab.com/gitlab-com/support/zendesk-global/macros/-/blob/master/active/Support/SaaS/GitLab.com/Account%20Ownership%20Verification%20-%20GitLab.com.md?ref_type=heads).

Any audit / log requests must be made by the owner of a top-level namespace. We should always use the Enterprise Owner macro in these requests.

### Step 2: Checking challenge answers

> **Note**: In case the user sends back very minimal information and it's clear it's not sufficient or the answers are vague, reply asking for more information immediately after their response. You can provide some additional guidance, such as "please provide the exact date and time of the commit, not just an approximate one".
@@ -71,16 +73,17 @@ Otherwise, use the [`Support::SaaS::GitLab.com::Account Ownership Verification -
1. Use the ZenDesk [GitLab Super App's](/handbook/eta/css/zendesk/apps/global#gitlab-super-app) `2FA Helper` to determine the [risk factor](https://internal.gitlab.com/handbook/support/#risk-factors-for-account-ownership-verification) (GitLab internal) based on the user's answers. Data classification criteria and any notes are in the [GitLab Internal Handbook - Data Classification table](https://internal.gitlab.com/handbook/support/#data-classification), which is considered the source of truth.
   - Challenge answers must be evaluated against a paid namespace if the user is a member of any paid namespace. If the user is not a member of a paid namespace, refer to [Conditions for 2FA Reset Consideration](../workflows/2fa-removal.md#conditions-when-account-is-used-to-access-customers-portal) for further guidance.
   - If a group owner is answering on an [enterprise user's](/handbook/support/workflows/gitlab-com_overview#enterprise-users) behalf, see the [Account verification matrix](#account-verification-matrix) for which account to evaluate the answers against. Even if the Enterprise user is not a current member of the paid namespace, the data classifcation is RED.
   - Audit and log requests for groups/projects should use the `General Account Verification` form since the `Enterprise owner verification` form is aimed toward user related action requests.
   - If you need to leave a comment manually (instead of through the app), use the [`Support::SaaS::GitLab.com::2FA::2FA Internal Note` macro](https://gitlab.com/gitlab-com/support/zendesk-global/macros/-/blob/master/active/Support/SaaS/GitLab.com/2FA/2FA%20Internal%20Note.md?ref_type=heads) to put an internal note on the ticket.

1. **If verification passed:** Request that your decision be peer-reviewed by another member of the team through Slack `#support_gitlab-com`. They will perform the steps in 3a
1. **If verification passed:** Request that your decision be peer-reviewed by another member of the team through Slack `#support_gitlab-com`.
1. **If the verification failed**: Move to step 3b

### Step 3a: User successfully proves account ownership

This section is typically done by the peer reviewer. If needed, the peer reviewer (or approving manager) may leave an approval note, in which case the original reviewer will perform the actions.
For reviews of 2FA removal or other user changes, the reviewer will typically complete the final action. Requests such as audit events or console escalation work will typically be handled by the original ticket owner.

1. If you agree with the decision, sign into your admin account and locate the username in the users table or by going to `https://gitlab.com/admin/users/usernamegoeshere`
1. If you agree with the decision to take action on a user, sign into your admin account and locate the username in the users table or by going to `https://gitlab.com/admin/users/usernamegoeshere`
      1. Please see [Account Changes workflow](../workflows/account_changes.md).
      1. Under the account tab, click `Edit`, add an [Admin Note](../workflows/admin_note.md), and save.