Assign least privilege
- Separate alert viewing, configuration, sending, cancellation, device management, and audit access.
- Require two-factor authentication for privileged and emergency-communications roles.
- Review dormant accounts and role assignments on a documented schedule.
Use audit evidence
Audit records identify the actor, tenant context, support-session context, action, relevant object, request identifier, and timestamp. Export only for an approved purpose and protect the resulting file according to organization policy.