cds-snc / notification-planning-core

Project planning for GC Notify Core Team
0 stars 0 forks source link

Create or refine query to surface simultaneous multiple logins of GCNotify from same account #241

Open jimleroyer opened 6 months ago

jimleroyer commented 6 months ago

Description

As an ops lead, I want to improve on detection of shared accounts within GCNotify, So that I can flag these and take appropriate actions.

WHY are we building?

Improve detection of shared GCNotify accounts.

WHAT are we building?

A query that can surface simultaneous logins from the same account. This can be from multiple logins in a short span of time or from different locations, or both. It depends on what we have as information in the system.

VALUE created by our solution

Better detection of shared account and improved security.

Acceptance Criteria

Given some context, when (X) action occurs, then (Y) outcome is achieved.

QA Steps

Related incident

https://docs.google.com/document/d/1_3Egk7ljIF5lH4z9RXLxElHn14G9LfuZ7z-hHwCsHZI/edit