Skip to main content
Review and revision metadata
Review Date: 2026-06-16
Reviewer: Operations Manager

previous version on gdrive

Overview: User Management & Research Support

1. Introduction & Regulatory Context

The myDRE ecosystem is fundamentally built as a cross-organizational collaboration platform. This architecture allows external researchers to securely cooperate within your organization's dedicated Workspaces, while your own internal personnel can be invited to collaborate within external environments. This flexible model operates in strict compliance with the Access Review Policy.

To meet institutional duty-of-care requirements under ISO/IEC 27001 Annex A.05.15, GDPR Article 24(1), and NIS 2 Directive Article 21-2(i), our user management infrastructure enforces three foundational assumptions:

  1. Corporate Domain Authority: An organization must have the unilateral ability to block individuals from accessing the platform using that organization's official email domain.
  2. Identity Decoupling: It is fully acceptable for a researcher to associate their standardized @mydre.org username with an updated or alternative secondary contact email address, provided it is verified.
  3. Accountability Gatekeeping: It is essential that an Accountable Member, Privileged Member, or Workspace Controller explicitly verifies and authorizes any changes to a user's identity details (such as name changes or contact email modifications) before technical action is executed.

2. Specialized Lifecycle Procedures

2.1 The Right to be Forgotten & Username Recycling

An individual's unique platform identifier follows a strict decommissioning lifecycle similar to a cellular telephone number:

  • The Communication Analogy: A mobile number connects directly to an individual. Once disconnected, that connection is broken, but the number cannot be immediately reassigned without risking misdirected communications.
  • The Cool-Down Mandate: Similarly, an assigned @mydre.org username serves as an active identification and routing token. When a user account is disassociated, anDREa enforces a strict cool-down period before allowing that specific username to be recycled or assigned to a different individual.
  • Operational Execution: Deactivated usernames are systematically preserved within anDREa’s Microsoft Entra ID database in accordance with the timelines defined in our Retention & Destruction Policy, while identity decoupling is tracked inside the myDRE user management framework.

2.2 Corporate Offboarding & Off-Group Access

  • SCIM Automation (Recommended Standard): anDREa strongly advises organizations to deploy System for Cross-domain Identity Management (SCIM) groups. When a user is removed from an enterprise SCIM group, blocked within an external Entra ID tenant, or deleted from an upstream corporate directory, the system automatically triggers a prompt to block that username within myDRE.
  • Non-SCIM Catch-Up Tracks: anDREa cannot natively prevent external users from using an organization's email domain when requesting a username. To bridge this visibility gap, administrators can download an audit log of active domain users by navigating to the secure portal at https://insights.andrea-cloud.com/client-dark and selecting My Employees. This CSV output can be manually cross-referenced against your active internal SCIM group to isolate unauthorized or unmanaged accounts.

3. User Story & Role-Based Action Matrix

The following matrix maps platform user stories to their required operational execution tracks across organizational roles:

User Story / ScenarioanDREa Admin RoleResearch Support (RS)Accountable / Privileged MemberEnd-User Track
User requires a new @mydre.org identityExecutes request via SCIM integration (single or bulk additions).Processes and initiates request via admin.mydre.org.In Development: Direct creation interface inside mydre.org.Submits formal access ticket to support.mydre.org.
User forgot their usernameAutomated self-service retrieval path via web utility.Refer user to retrieval path.Refer user to retrieval path.Accesses standard recovery tool at https://isms.andrea-cloud.com/forgot-username.
Established user needs password resetInfrastructure handled via federated identity pathways.Refer user to native Microsoft enterprise tooling.Refer user to native Microsoft enterprise tooling.Completes standard recovery via https://passwordreset.microsoftonline.com/.
New user requires initial credentialResets temporary password string and emails user.Escalates request by submitting an operational support ticket.Escalates request by submitting an operational support ticket.Requests credential token via support.mydre.org.
User requires MFA authenticator resetResets MFA registration and sends instructions to user.Submits an escalation ticket directly to anDREa support.Submits an escalation ticket directly to anDREa support.Requests reset via institutional support structures.
User requests new hardware key or custom MFASystem administration configuration.Refer user to profile management options.Refer user to profile management options.Configures credentials directly at https://myaccount.microsoft.com/?ref=MeControl.
User requests modification to "Other Email" fieldProcesses backend data modification request.In Development: Direct creation and tracking inside admin.mydre.org / SCIM.In Development: Validates if the user retains authorization to access active workspaces.Submits formal account amendment request to support.mydre.org.*
Immediate account blocking requiredSecurity Officers execute immediate lockout via active phone escalations to +31 6 2125 3834 or +31 6 4812 1117.Escalates to Security Officer immediately.Escalates to Security Officer immediately.N/A
Remove user from one or more WorkspacesPerforms manual cleanup if automated processes fail.In Development: Activates temporary privileged workspace roles via PIM.Manages active directory lists via the native Users tab inside mydre.org.Performs self-removal or submits request inside the dashboard.
User leaves company / Loses access to corporate emailProcesses backend modifications following ticket validation.Submits an authorized ticket detailing required alternate contact email.Submits an authorized ticket detailing required alternate contact email.SCIM: Account is disabled automatically via internal tenant deletion loops.
Deactivate user inside core platform directoriesExecutes complete deactivation sequence inside admin.mydre.org.Submits deactivation request via operational channels.Submits deactivation request via operational channels.Requests account closure via ticket submission.
Add user to an active WorkspaceStandard maintenance support.In Development: Captures temporary privileged workspace roles via specialized PIM.Direct management via the native Users tab in mydre.org (supports both @mydre.org and direct emails).Accepts workspace invitation token.
Purge records under Right to Be ForgottenDeletes user records from Entra ID based on the Retention & Destruction Policy.N/AN/AInitiates formal compliance erasure request via ticket.

* Critical Privilege Guard: When a user's verified "Other Email" parameter is changed, the platform automatically downgrades that user's access rights to Restricted across all active workspaces. Access remains restricted until their profile clearance is re-verified by the workspace Accountable Member.


4. Automated Governance & Exception Controls

  • Inactivity Gates: Users who fail to authenticate for a predefined period of months receive automated email notifications. If no action is taken, their access profile is automatically blocked.
  • Unverified Contact Fields: Accounts holding unverified or missing "Other Email" parameters are marked within the administrator interface. It is up to the Workspace Accountable or Privileged Member to review these flags and determine whether the researcher may remain in the collaborative workspace.
  • Continuous Compliance Scans: In Development: Users will be required to complete periodic re-verification prompts to confirm they retain active, authorized control over their listed institutional email endpoints.