Skip to content

[Incident] Add ADMIN validation for templates containing links#3467

Description

@connorscarolyns

馃敡 Incident Action Item

馃幆 Action Required

Description of Action Item:

Add content guidance and validation to the ADMIN template creation/editing experience for SMS templates containing links.

When a user creates or edits an SMS template containing a link, surface the applicable disclosure requirement and identify templates that appear not to meet it before the template is saved.

Type of Action:

  • Fix / Remediation
  • Mitigation
  • Hardening / Resilience
  • Monitoring / Alerting
  • Documentation Update
  • Process / Governance
  • Other: ___

馃У Incident References

Incident Slack Channel:
https://gcdigital.slack.com/archives/C0BSDQD86PR

Post-Mortem Document:
https://docs.google.com/document/d/1G1YGz72iwJC9h1BVWXpPFHDoHduvQr38j0AxvDXyp1g/edit?usp=sharing


馃帥 Current Mitigations in Place and Risk Assessment

Existing templates identified through the incident are being corrected manually.

There is currently no equivalent guardrail in ADMIN to alert team members when creating or editing an SMS template that introduces a link without the required disclosure.

Risk of Recurrence:

  • High
  • Medium
  • Low

Potential Impact (if it happens again):

  • System stability
  • Notifications delivery
  • User experience
  • Security / privacy
  • Operational burden

鉁旓笍 Definition of Done

  • ADMIN identifies when an SMS template contains a link
  • Applicable disclosure guidance is shown during template creation/editing
  • ADMIN warns or prevents saving when a detectable requirement is not met, based on the agreed validation approach
  • Validation works for both new and existing templates being edited
  • Behaviour is tested with representative English, French, and bilingual templates
  • Relevant ADMIN documentation or operational guidance is updated
  • Risk owners confirm closure

馃摝 Additional Notes

This action provides an internal operational guardrail for templates created or modified through ADMIN.

It should align with the user-facing template validation rules so that ADMIN and the sender-facing product do not apply conflicting requirements.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    IncidentFor all Incident-related tickets, including Incident Actions.

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions