Protecting customer data remains a top priority at Hyland. As part of our ongoing commitment to security and compliance, we are making an important change to how Hyland Technical Support accesses customer environments. Effective immediately, Hyland Technical Support will no longer have access to customer environments using shared or Hyland-managed credentials. Going forward, customers must provide and manage access whenever Technical Support requires direct interaction with a customer system. This change strengthens security by ensuring customers maintain direct control over who is granted access, what access is provided, and how long that access remains available. It also reduces the risks associated with shared credentials and aligns with industry security best practices. What's Changing? In the past, some customers allowed members of the Technical Support team to access their environments using credentials managed by Hyland. Going forward, access to customer environments must be granted and controlled by the customer. This policy applies to all customer environments, including: Production Development Test QA Staging Disaster Recovery (DR) Other non-production environments This change helps: Ensure customers maintain ownership and control of privileged access. Reduce risk associated with persistent or shared credentials. Improve accountability and auditability of access activities. Align with modern security and compliance practices. Available Access Options When Technical Support requires access to a customer environment for troubleshooting or investigation purposes, customers should use one of the following methods. Option 1: Customer-Present Support Session Customers may schedule a remote support session and grant access while a customer representative is present. This approach is well suited for: Troubleshooting issues Reviewing configurations Demonstrating reported problems Investigating system behavior Activities where customer oversight is required Option 2: Temporary Customer-Managed Access Customers may create a temporary account for the specific Technical Support engineer assigned to their case. This option allows Support to perform investigations that may take place over several hours or multiple days without requiring a customer representative to be continuously present. This approach is well suited when: Your organization's security policies permit temporary third-party access. Troubleshooting activities are expected to take an extended period of time. Logs, configurations, integrations, or system behavior need to be reviewed over time. Scheduling a live support session is impractical due to time zones or resource availability. Technical Support requires the flexibility to perform investigations asynchronously. Customers should be aware that this approach provides the assigned Technical Support engineer with direct access to the environment during the authorized period and may not provide the same level of real-time oversight as a customer-present support session. Customers should determine whether this access model aligns with their internal security and compliance requirements. We recommend that temporary access: Be limited to the permissions required for the investigation. Be assigned to a named Technical Support engineer whenever possible. Have a defined expiration date. Be revoked when the support activity is complete. For customers using Nuxeo, a temporary user account can typically be created by an administrator by navigating to Administration > Users & Groups, selecting New, entering the user's details, assigning the appropriate groups or permissions, and either setting a temporary password or sending an invitation for the user to activate their account. What This Means for Support Requests Our commitment to helping customers resolve issues remains unchanged. However, customers may need to provide or arrange access before certain investigations can begin. To help avoid delays, customers should ensure they have an established process for granting temporary access when support engagements require direct interaction with their environment. It is important to note that some administrative activities remain the responsibility of Hyland Cloud Operations teams and are not performed by Technical Support. Examples may include platform-level maintenance or operational tasks such as a full Elasticsearch reindex. When assistance from the Cloud team is required, customers should submit a Support ticket and select "Cloud Services Request - Configuration" from the Product Module dropdown. This will ensure the request is routed to the appropriate team for review and scheduling. While Technical Support may help identify when a Cloud Services request is needed, tasks performed by the Cloud team will continue to be handled through the established service request process. Frequently Asked Questions Can Hyland still assist with troubleshooting and issue resolution? Yes. This change affects how access is granted, not the support services available to customers. Technical Support will continue to assist with issue investigation and resolution using customer-approved access methods. Does this apply only to production environments? No. This policy applies to all customer environments, including production and non-production environments such as development, test, QA, staging, and disaster recovery environments. Customers should follow their organization's security policies whenever granting access to Technical Support personnel. Our Commitment Security is a shared responsibility. By transitioning to customer-controlled access, we can better protect customer environments while continuing to provide the high-quality support our customers expect from Hyland. If you have questions regarding this change or need assistance determining the best access method for a support engagement, please contact Hyland Technical Support.