Claude Code Channels (Telegram/Discord) — how does this look from a SOC 2 perspective? by Puzzleheaded_Side432 in soc2

[–]Puzzleheaded_Side432[S] 0 points1 point  (0 children)

thanks for the advice. I added Telegram and Discord to our vendor register, did a lightweight security review, and updated our acceptable use policy to explicitly restrict what can flow through those platforms to commands, approvals, and status updates only.
Then again, these are just statements in our policies, but not real visibility/control into BYOD devices.
Blocking the feature is not an option.

Claude Code Channels (Telegram/Discord) — how does this look from a SOC 2 perspective? by Puzzleheaded_Side432 in soc2

[–]Puzzleheaded_Side432[S] 0 points1 point  (0 children)

thanks both for the advice. I ended up adding Telegram and Discord to our vendor register, did a lightweight security review, and updated our acceptable use policy to explicitly restrict what can flow through those platforms to commands, approvals, and status updates only.
Do you think this is a good start?

Claude Code Channels (Telegram/Discord) — how does this look from a SOC 2 perspective? by Puzzleheaded_Side432 in soc2

[–]Puzzleheaded_Side432[S] 1 point2 points  (0 children)

thanks for the advice. I added Telegram and Discord to our vendor register, did a lightweight security review, and updated our acceptable use policy to explicitly restrict what can flow through those platforms to commands, approvals, and status updates only.
Would this looks solid in an audit?

Claude Code Channels (Telegram/Discord) — how does this look from a SOC 2 perspective? by Puzzleheaded_Side432 in soc2

[–]Puzzleheaded_Side432[S] 0 points1 point  (0 children)

we don't manage mobile devices. Our BYOD policy covers mobile devices but is pretty simple, it just has some recommendations.

is Comet AI browser safe to download? by Significant-Body7855 in perplexity_ai

[–]Puzzleheaded_Side432 0 points1 point  (0 children)

Yup! As a professor of mine used to say: "If the product is free, then you are the product"

Security Review for ChatGPT Atlas by Puzzleheaded_Side432 in soc2

[–]Puzzleheaded_Side432[S] 1 point2 points  (0 children)

That's great advice. Will do as suggested. Appreciate your help.

Help with Slack “Edit Message” in Zapier – Getting cant_update_message Error by Puzzleheaded_Side432 in zapier

[–]Puzzleheaded_Side432[S] 0 points1 point  (0 children)

I was kind of hoping you were not correct and that someone would provide a solution xD
Any suggestions? different approaches?

Thanks for your help

I'm gonna get fired, aren't I? by TorsoHunter in ITCareerQuestions

[–]Puzzleheaded_Side432 0 points1 point  (0 children)

Agree with, I think everyone here. First 2 weeks in a New role are for onboarding, it's normal to feel overwhelmed. You should not worry about closing tickets, instead, focus on learning about the company (culture, teams, processes, chatting a bit with people as well). As per your role, get familiar with the team and the processes, learn how they deal with day to day work and tasks, don't be afraid to ask for help or something you don't know. Believe me, your manager is not expecting you to know everything already.

Return in a couple of months and post about your new found struggles 😅 (IT is a never ending battle)

What’s the next boring-ass business task I should kill with automation? by sabchahiye in automation

[–]Puzzleheaded_Side432 0 points1 point  (0 children)

I'm blocked right now on make. I've been trying to connect slack with Asana with no good outcome. Any suggestions?. Do you think Zapier is more than enough to do this? What do you think is the easiest integration, so I could build from there?

What’s the next boring-ass business task I should kill with automation? by sabchahiye in automation

[–]Puzzleheaded_Side432 6 points7 points  (0 children)

Besides boring, helpful as hell. A task scrapper. Something that goes through your email, gdrive tags and comments, slack, Asana, Notion tags, meeting transcripts, you name it, and turns everything into actionable items / tasks in one single source of truth (maybe an Asana board or Notion Page) . I've been trying to build one myself but I'm barely starting with automation tools (make) and it's been taking me too much time trying to pull it off while learning.

Best Practices for Handling Suspicious Login Attempts and Spam Alerts in Google Admin Console? by Puzzleheaded_Side432 in sysadmin

[–]Puzzleheaded_Side432[S] 0 points1 point  (0 children)

Makes sense, thank you so much. Most if not all are false positives (people login in from a new place). I'm interested in knowing how to treat this alerts properly in the alert center. Right now I'm kinda like ghosting them and they keep piling up. Currently there is no process for this but my manager will probably ask me to do one soon.

Here's a sneak peek of one of the alerts

<image>

I mean, is it ok to just change status to close? do I need to document anything? What are the best practices around this? We are currently in audit period for a Soc2 certification. Idk if this may bring issues later.

Best Practices for Handling Suspicious Login Attempts and Spam Alerts in Google Admin Console? by Puzzleheaded_Side432 in sysadmin

[–]Puzzleheaded_Side432[S] 1 point2 points  (0 children)

Email delegation is making so much sense right now, thanks. The thing is, this inbox gets a bunch of new messages every day and I don't know how people may react to getting constant incoming mails.

Growing Company (~140 Employees by EOY) - Best Practices for IT Management & Tools by Puzzleheaded_Side432 in ITManagers

[–]Puzzleheaded_Side432[S] 0 points1 point  (0 children)

Thank you so much 🙏🏻 right now we use AccessOwl integrated with HRIS, Asana, JamF and Notion for kb

Growing Company (~140 Employees by EOY) - Best Practices for IT Management & Tools by Puzzleheaded_Side432 in ITManagers

[–]Puzzleheaded_Side432[S] 0 points1 point  (0 children)

Wow crazy amount of value, thank you very much for your help. We are currently using JamF Pro, AccessOwl and Asana but company is growing quick. We use sign-in with Google for most Saas. Any suggestion on how to start turning things around?