Observe — read onlyYou are inside Achimota School
Acting as
No one — observing as yourself
Reason
Applicant cannot see their status
Ticket
EG-24817
Every action is logged as
Efua Mensah
Time leftSession expires at 26 Aug 2026, 14:42.
enrollghana
Signed in as Efua Mensah

Session sup_03 · EG-24688

Accra Technical University

Act session opened 25 Aug 2026, 12:58, ended 25 Aug 2026, 13:26 after 28 min.

Act — can writeEnded

Entered under break glass — FR-M12-12

This session did not wait for the institution’s consent. It was authorised by a named CS Supervisor on a security reason, the institution was told at the moment of entry, and it goes to supervisor review whether or not anything was found. Break glass does not lift the ceiling — everything excluded below stayed excluded.

What this session is

Recorded permanently
Institution
Accra Technical University
Support policy
always allowed
Ticket
EG-24688
Reason code
Suspected security incident
Support agent
Yaw Darko
Acting as
S. O. · School Admin

Masked · FR-M12-05

Opened
25 Aug 2026, 12:58
Ended
25 Aug 2026, 13:26

Justification, as written

Two hundred sign-in attempts against ATU staff accounts from one address inside four minutes. Tenant contact unreachable at 02:10. Entered under break glass to establish whether any account was taken over.

Accra Technical University can read this, verbatim, alongside everything the session did.

Applications in this institution

0 visible

A support session can never see more than the institution's own staff, and staff never see an application the applicant has not submitted. Drafts are filtered out at the data layer, not hidden in the markup — BRD §3.4.

This institution has no submitted applications in the current cycles.

What you can and cannot do here

FR-M12-06 · default deny

Every control is asked of one table before it is drawn. A capability the table does not mention is refused — absence is a refusal, not an oversight. Nothing is hidden from you; you are shown the refusal and the clause behind it.

Open masked application

Read the application's status, timeline and masked applicant details.

AC-CS-01Permitted by the impersonation ceiling.

Change an answer the applicant gave.

  • FR-M12-06fOnly the institution's own staff may change an application.

View or download a file the applicant uploaded.

  • FR-M12-06a / AC-CS-04Excluded from support access — applicant identity documents are never viewable or downloadable from a support session.

Make an offer, or decline the application.

  • FR-M12-06fOnly the institution's own staff may issue a decision.

Change the account the institution's fees are paid into.

  • FR-M12-06b / AC-CS-05Where an institution's money is paid can never be changed from support.

Record a payment against the application.

  • FR-M12-06cSupport cannot issue a payment.

Refund or void a collected fee.

  • FR-M12-06cSupport cannot reverse or amend a payment.

Download the cycle register as a file.

  • FR-M12-06dRegisters cannot be exported from a support session.

Remove an entry from the tenant's audit trail.

  • FR-M12-06eAudit records cannot be deleted by anyone, support included.

Add a colleague to the institution's team.

  • FR-M12-06gSupport cannot invite staff to a tenant.

Revoke a colleague's access to the institution.

  • FR-M12-06gSupport cannot remove a tenant's staff.

Alter the tenant's sign-in and multi-factor rules.

  • FR-M12-06hA tenant's own security settings can only be changed by the tenant.

Send the applicant's last SMS or email again.

  • FR-M12-06c — default denyNothing in the impersonation ceiling grants this, so it is denied. Capabilities are added to the ceiling reviewably, one at a time — absence is a refusal, not an oversight.

No rule for this capability exists in the ceiling. Default deny.

Read a former student's record held by this institution.

  • FR-M12-06c — default denyNothing in the impersonation ceiling grants this, so it is denied. Capabilities are added to the ceiling reviewably, one at a time — absence is a refusal, not an oversight.

No rule for this capability exists in the ceiling. Default deny.

Act mode does not currently unlock a single write

Every write in the ceiling is seated at permitted: false, so an Act session today can read and nothing more. That is the default-deny design working, not a gap: capabilities are added to the ceiling one at a time, each with the clause that justified it (TSD §13.4). Act still exists, is still separately approved, and is still reviewed — because the day a write is granted, the approval and the review have to already be there.

Everything this session did

5 entries

Recorded against both identities — yours and the account acted as — including the attempts that were refused. The record cannot be edited or deleted by anyone, support included (FR-M12-13, FR-M12-14).

WhenWhoWhatOutcome
25 Aug 2026, 13:26Yaw Darkoacting as S. O.Session ended. Tenant contacted on the escalation line and asked to enable MFA themselves.support_session · UPDATEPermittedFR-M12-11
25 Aug 2026, 13:14Yaw Darkoacting as S. O.Attempted to suspend the staff account showing the failed sign-ins.staff_user · UPDATERefusedFR-M12-06g
25 Aug 2026, 13:09Yaw Darkoacting as S. O.Attempted to force multi-factor authentication on for all ATU staff.tenant_security_setting · UPDATERefusedFR-M12-06h
25 Aug 2026, 13:01Yaw Darkoacting as S. O.Read the tenant sign-in audit trail for the incident window.audit_event · SELECTPermittedFR-M12-12
25 Aug 2026, 12:58Yaw Darkoacting as S. O.Break-glass entry authorised by Naa Ashiley Quaye, CS Supervisor.support_session · INSERTPermittedFR-M12-12

Back to diagnostics · Supervisor review queue