Privacy-Safe Workhuman Support Bundle
Overview
Create the minimum reproducible evidence package needed by customer teams or Workhuman support without exposing workforce data, messages, awards, balances, or credentials.
Prerequisites
- Incident identifier, bounded time window, tenant and environment, symptom, severity, and support owner
- Customer classification, retention, disclosure, and legal requirements
- Current contract or connector documentation and an approved sharing channel
Tool Discipline
Use Read, Glob, and Grep for local evidence discovery, WebFetch to verify current vendor context, and Write or Edit only inside an access-controlled redacted bundle.
Current Contract
Workhuman processes workforce, recognition, reward, and integration data and publishes privacy and security commitments. Support evidence must follow the customer's agreement and support process; public pages do not authorize unrestricted log or payload sharing.
Authentication
Do not collect credentials, authorization headers, session cookies, client secrets, signed URLs, or reusable tokens. Hash or truncate identifiers only when the receiving owner confirms that they remain useful.
Instructions
- Define the diagnostic question, audience, time window, allowed data classes, retention, and deletion owner.
- Inventory candidate logs, configuration, contract fingerprints, deployment history, connector runs, reports, and safe correlation fields.
- Exclude names, recognition messages, employment details, balances, addresses, financial data, secrets, raw payloads, and unrelated tenants.
- Create a UTC timeline containing expected behavior, actual behavior, last success, first failure, changes, retries, and partial effects.
- Include secretless topology, environment and version identifiers, schema digests, counts, sanitized statuses, and synthetic reproduction steps.
- Run pattern and manual redaction review; record excluded classes and the reviewer.
- Package a manifest with hashes, purpose, audience, expiry, and approved transfer channel.
- Obtain disclosure approval before sending and record receipt and deletion expectations.
Approval Boundaries
Do not query extra personal data, widen the incident window, decrypt archives, or send the bundle outside approved channels without privacy and support-owner approval.
Output
Return the redacted timeline, safe configuration and topology, reproduction, schema and correlation evidence, manifest hashes, redaction proof, approvers, expiry, and transfer receipt.
Error Handling
| Condition | Response |
|---|---|
| Necessary evidence is personal data | Minimize or tokenize it and obtain explicit disclosure authorization. |
| Bundle cannot reproduce the issue | State the limitation and request one narrowly defined additional artifact. |
| Secret scan finds a credential | Quarantine the bundle, rotate if exposed, redact, and rescan. |
Example
A redacted completion receipt might look like this:
incident=WH-42; window=15m; records=redacted-counts-only; secrets=0; manifest=sha256:...; approved=privacy+support; expires=7d
Resources
Next Steps
Track the vendor response against the manifest and delete the bundle at the approved expiry.