Jul 17
Explicit support-access consent & Time-limited support access.
One of the things I am impressed by is Redbark’s privacy-first architecture. The fact that transaction data isn’t stored and support debugging is sandboxed is a significant differentiator for me.
I’d love to see that philosophy extended to support access.
My suggestion is that access to sandboxed transaction data is an explicit, user-managed consent rather than being implied when a support request is raised.
For example:
Customer raises a support request.
Redbark advises that transaction data is required to diagnose the issue.
The customer explicitly grants access (e.g. 24 hours, 7 days or until revoked).
Access is automatically revoked when the consent expires.
All support access is visible to the customer together with who accessed the data, when and for what purpose.
This could potentially sit under the existing Consents model alongside Open Banking permissions.
From a technical perspective I’m not sure it materially changes the security model, however I think it materially improves transparency, informed consent and user trust.
Ironically, I think this could become a competitive advantage for Redbark. Rather than asking users to simply trust the product, it gives them direct control over when support access is permitted.
As a privacy-conscious user, I would feel considerably more comfortable knowing that support access is always explicit, time-limited and user managed.
Completed
This has been completed! Thanks for the feedback. This toggle lives under the http://app.redbark.com/settings/consents page!