QuestGlass staff access policy
Staff tools can expose sensitive account, report, moderation, and safety information. Production staff access must use verified email, role-based access, active staff records, multi-factor authentication, and audit logging.
- Production staff MFA is required
- Every sensitive staff action should include an audit reason
- Access should be reviewed regularly and removed when no longer needed
Access requirements
Staff members must use their own account, verified email, assigned role, active staff record, and multi-factor authentication in production.
Least privilege
Roles should be limited to the minimum needed for support, moderation, content, analytics, or elevated operations. Staff must not browse user data out of curiosity.
Audit and review
User detail views, report actions, content removals, membership changes, broadcasts, account actions, and staff changes should be written to audit logs and periodically reviewed.
Incident response
Suspected staff misuse, data exposure, account compromise, or breach must be escalated immediately, investigated, contained, and reviewed for legal notification duties.
Explore QuestGlass
Public policy text is available here without JavaScript. Interactive accounts, maps, chat, and settings still require the app.