QuestGlass

QuestGlass staff access policy

Staff tools can expose sensitive account, report, moderation, and safety information. Production staff access must use verified email, role-based access, active staff records, multi-factor authentication, and audit logging.

Last updated: July 5, 2026

  • Production staff MFA is required
  • Every sensitive staff action should include an audit reason
  • Access should be reviewed regularly and removed when no longer needed

Access requirements

Staff members must use their own account, verified email, assigned role, active staff record, and multi-factor authentication in production.

Least privilege

Roles should be limited to the minimum needed for support, moderation, content, analytics, or elevated operations. Staff must not browse user data out of curiosity.

Audit and review

User detail views, report actions, content removals, membership changes, broadcasts, account actions, and staff changes should be written to audit logs and periodically reviewed.

Incident response

Suspected staff misuse, data exposure, account compromise, or breach must be escalated immediately, investigated, contained, and reviewed for legal notification duties.

Explore QuestGlass

Public policy text is available here without JavaScript. Interactive accounts, maps, chat, and settings still require the app.