Account suspension deactivation withdrawal » History » Version 4
Tom Clegg, 09/01/2011 12:31 PM
1 | 2 | Tom Clegg | h1. Account suspension, deactivation, withdrawal -- desired behavior |
---|---|---|---|
2 | 1 | Tom Clegg | |
3 | h2. Clarify definitions/implications of various states participants can be in. |
||
4 | |||
5 | *Active* users are enrolled and |
||
6 | * were enrolled less than 4 months ago; _or_ |
||
7 | * have submitted enough safety questionnaires recently, i.e., |
||
8 | ** submitted one SQ in the last 4 months; _or_ |
||
9 | ** submitted three SQs in the last 12 months. |
||
10 | * note: this can still result in: Jan1-enroll, Apr1-SQ, Aug1-deactivate. |
||
11 | |||
12 | *Not active* = *deactivated*. |
||
13 | |||
14 | *Deactivated* users cannot "access" their accounts. The word "deactivation" is defined in the consent doc. Specifically, they: |
||
15 | * _can_ log in |
||
16 | * _can_ change their email addresses |
||
17 | * _can (?)_ change their designated proxy, shipping address, (?) |
||
18 | * _cannot_ upload genetic data |
||
19 | * _cannot_ alter their public profiles |
||
20 | |||
21 | 3 | Tom Clegg | *Suspended* users are not included in public data releases (e.g., the list of public profiles). Users can become suspended by: |
22 | * manual intervention by admin |
||
23 | * withdrawing and selecting "remove profile data" |
||
24 | |||
25 | *Withdrawn* users are deactivated _and_: |
||
26 | * _cannot_ change and _do not see_ their designated proxy, shipping address, ... |
||
27 | * _cannot_ be self-reactivated by filling in SQs etc |
||
28 | * _can_ be reactivated by an admin (e.g., after a forged or accidental withdrawal) |
||
29 | * are not necessarily suspended (only if they ask for data removal) |
||
30 | 1 | Tom Clegg | |
31 | h2. Help participants understand what to expect. |
||
32 | |||
33 | * A suspended user's home page should specify very clearly what "not in public data release" means. |
||
34 | * A deactivated user's home page should explain why (and how) email address etc. can still be updated; hide all stuff that can't be changed; and, if the account is not suspended, provide a link to the public profile page. |
||
35 | * It should be clear why/when your account was deactivated, reactivated, etc. |
||
36 | 4 | Tom Clegg | * There is always at least 1 month between "start prompting for safety questionnaire" and "deactivated". During this time, the participant should be reminded of the conditions for, and consequences of, deactivation. |
37 | 1 | Tom Clegg | |
38 | h2. Encourage researchers/browsers to look at "active" participants |
||
39 | |||
40 | * Display "active PGP participant" indicator, in glowing green pulsating aura or whatever, on public profile pages |
||
41 | * Allow browsing of both "active" and "inactive" public profiles, but make "active" the default choice |
||
42 | 4 | Tom Clegg | |
43 | Rationale: Better to reward users for being active than to punish them for being inactive. Don't come across as demanding, unappreciative, etc. |
||
44 | 1 | Tom Clegg | |
45 | h2. Rules for email contact |
||
46 | |||
47 | Currently, Jason pulls email lists out of Tapestry using whichever criteria are appropriate for the message at hand. |
||
48 | |||
49 | Tapestry also needs to know whether it's appropriate to send email to a given participant/user. Examples: |
||
50 | * users deactivated for SQ-lapse should still get SQ reminders |
||
51 | * ...but should not(?) receive other participant communications |
||
52 | * users deactivated by admins should not receive SQ reminders |
||
53 | * deactivated users should(?) be able to send themselves password-reset emails |
||
54 | * withdrawn users should(?) be able to send themselves password-reset emails |
||
55 | |||
56 | h2. Use cases to review |
||
57 | |||
58 | * Auto-deactivate due to SQ lapse |
||
59 | * Auto-reactivate by submitting SQ |
||
60 | * Admin suspend+deactivate in response to "please remove my data" email, or PGP decision that participant might not have provided proper consent and review is needed |
||
61 | * Admin reinstate suspended/deactivated account |
||
62 | * Participant withdraws without requesting data removal |
||
63 | * Participant withdraws and requests data removal |