Welcome to the new MongoDB Feedback Portal!
{Improvement: "Your idea"}
We’ve upgraded our system to better capture and act on your feedback.
Your feedback is meaningful and helps us build better products.
We’ve upgraded our feedback system to better capture, track, and act on your feedback. Here’s what you need to know:
MongoDB Atlas compliance backup policies have a "security or legal representative" attached that is the only person allowed to ask to disable it, lower its constraints, or delete backups that it safeguards. This goes with a specific verification process.
As stated in the doc (emphasis mine):
To disable a Backup Compliance Policy, the security or legal representative specified for the Backup Compliance Policy must open a case to request support and complete an extensive verification process.
The documentation says nothing about what the extensive verification process is. Should the representative be ready to send ID documents scans for validation? Is having access to their emails enough? Is there a time constraint on the for the process answers?
Not having more details means it's harder to get the person declared as the legal representatief ready before the need arises This is amplified by the fact that it's something that should happen pretty rarely if ever, and that the legal representative declared might not be the most tech savy person in the room.
It would be nice if such an important and precisely-bounded process was documented.
Ultimately, if this doesn't get adressed, we'll have to resort to triggering the process just for the sake of knowing what it is and documenting it on our side, but we'd rather avoid having to spend time on that :)
The public-facing documentation for disabling the Backup Compliance Policy is intentionally high-level to avoid exposing the details and exact steps that could be misused by a bad actor. For security reasons, we do not plan to expand this level of detail in the docs. However, if you would like to validate the behavior, you're welcome to run your own tests to understand the end to end process.