I realized that when customer support access our accounts, they can just access it on the fly and there are no restrictions. They just request for the relationship number and that's it. We're not sure what the support team or admins are able to do and see.
  1. Can we please have a 2FA permission whenever a support or any admin access an account? It's kind of like a prompt saying "support is trying to access your account, allow?" If I don't click yes or give the OTP code. Then support can not access.
  2. The account access will expire and will need to request for authorization to access again.
  3. Every action is logged.
Questions:
  • Do we have transparent logs for these types of interactions?
  • How can we increase our security measures against insider attacks today?