Clarify unverified case cleanup
This commit is contained in:
parent
17c93fa2f4
commit
7130be3b69
|
|
@ -54,8 +54,15 @@ workspace through PubSub and do not generate one operator email per message.
|
||||||
Exact repeats of the same unverified public support submission are represented
|
Exact repeats of the same unverified public support submission are represented
|
||||||
by one pending row. Its temporary fingerprint is a SHA-256 digest of normalized
|
by one pending row. Its temporary fingerprint is a SHA-256 digest of normalized
|
||||||
form fields; it is cleared on verification and does not replace the original
|
form fields; it is cleared on verification and does not replace the original
|
||||||
record or its audit history. Existing unverified rows are quarantined rather
|
record or its audit history. A pending support request or an emailed removal
|
||||||
than deleted because no retention policy has been approved.
|
notice that is still unverified after
|
||||||
|
`PUBLIC_CONTACT_VERIFICATION_MAX_AGE_SECONDS` is deleted by the maintenance
|
||||||
|
worker together with its creation audit entry. This verification-lifecycle
|
||||||
|
cleanup does not delete confirmed cases. A permitted no-contact report of
|
||||||
|
sexual material involving a minor has no mailbox to verify, enters the urgent
|
||||||
|
staff queue immediately, and is therefore outside this unverified-contact
|
||||||
|
cleanup. Retention or erasure of verified and no-contact case records remains
|
||||||
|
disabled until an applicable policy is approved.
|
||||||
|
|
||||||
Email-link verification establishes access to the mailbox, not government
|
Email-link verification establishes access to the mailbox, not government
|
||||||
identity, authority to act for another person, or the truth of the claim.
|
identity, authority to act for another person, or the truth of the claim.
|
||||||
|
|
|
||||||
Loading…
Reference in New Issue
Block a user