Skip to content

Commit 2c73999

Browse files
authored
Merge pull request #3392 from Scalingo/fix/IRQ-446/SNC-domain-whitelist-availability
[IRQ-446] Answering the need to clarify allow-listing domain procedure
2 parents 52ac156 + 1eb433d commit 2c73999

File tree

1 file changed

+24
-9
lines changed

1 file changed

+24
-9
lines changed

src/_posts/security/procedures/2000-01-01-secnumcloud.md

Lines changed: 24 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,7 @@
11
---
22
title: Getting access to SecNumCloud Region
33
nav: SecNumCloud
4-
modified_at: 2025-02-12 00:00:00
4+
modified_at: 2025-10-23 00:00:00
55
tags: security procedures secnumcloud
66
---
77

@@ -24,23 +24,38 @@ tags: security procedures secnumcloud
2424
- Reason of requesting the access
2525
3. A first answer will be provided under 7 business days
2626
4. _First-time domain or project registration only:_ an identity verification will be conducted.
27-
Have the Identity Document of the new app owner ready or use official tools like [France Identité](https://france-identite.gouv.fr/justificatif/)).
27+
Have the Identity Document of the new app owner ready or use official tools like [France Identité](https://france-identite.gouv.fr/justificatif/).
2828
If the requester is not the owner, the owner will have to also contact directly the support.
2929

3030
Note: this identity verification will take place each time a new domain is added to the SecNumCloud region.
3131

3232
## Can my user get access to the `osc-secnum-fr1` region?
3333

34-
A standard user cannot access `osc-secnum-fr1`, your user has to be allow-listed first.
34+
A standard user cannot directly access `osc-secnum-fr1`: your user account must first be allow-listed.
3535

3636
### Pre-conditions
3737

38-
- The user must have a legitimate reason to access the `osc-secnum-fr1` region:
39-
create or collaborate an application hosted in this region
40-
- The user must act as an employee of a company, using his/her company email (domain verification ensures that the organization controls the specified domain, allowing us to authenticate email communications sent on behalf of the company)
38+
- The user must have a legitimate reason to access the `osc-secnum-fr1` region, such as creating or collaborating on an application hosted there.
39+
- The user must act as an employee of a company, using a verified company email address (domain verification ensures that the organization controls the specified domain, allowing us to authenticate communications sent on its behalf).
40+
- The company domain must already be associated with at least one existing application in the `osc-secnum-fr1` region, or be declared as owned by the organization.
4141

4242
### Procedure
4343

44-
1. The owner of the application must invite you as a collaborator
45-
2. You must contact the support using standard means (email or chat)
46-
3. An answer will be provided within 2 business days
44+
#### Access through an existing application
45+
46+
- If your company already hosts one or more applications in the `osc-secnum-fr1` region, the application owner can invite you directly as a collaborator.
47+
- If your company domain is not yet allow-listed, you may ask the support team to register it. Once validated, all users from that domain will be eligible to access the region without further access confirmation needed from the support.
48+
49+
#### Access without allow-listed domain
50+
51+
- If your company domain has not been declared or allow-listed, the request must still come from the application owner.
52+
- The owner of the application must invite the user as a collaborator.
53+
- The user must contact the support using standard means (email or chat) to request access.
54+
- The support team will need the owner to confirm the request before granting access.
55+
56+
#### Domain declaration and regularization
57+
58+
- To simplify future user additions or removals, a company may request domain allow-listing (or submit a list of specific users) through the support channel (email or chat).
59+
- The domain must already be associated with an existing Scalingo account or application; we do not pre-register unregistered domains from Scalingo services.
60+
61+
An answer will be provided within two business days.

0 commit comments

Comments
 (0)