Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Managing Identity in Customer Service Operations: Allow Customer Service Agents to login as an end-user #40

Open
iglazer opened this issue Apr 25, 2021 · 2 comments
Milestone

Comments

@iglazer
Copy link

iglazer commented Apr 25, 2021

I disagree with the hard assertion that you should not let an agent login as user. “Login As” has its place if it is balanced with appropriate controls. This depends, in some cases, whether the agent is external or internal facing.

@iamJpRowan
Copy link

@iglazer, do you have any specific examples where "login as" is more appropriate than "on behalf of", and or what controls you think would offset the risk of not having a means to audit the true actor in a case where they are logging in as?

@iglazer
Copy link
Author

iglazer commented Apr 28, 2021 via email

@hlflanagan hlflanagan added this to the BoK Issue 8 milestone Mar 7, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants