myOTP App work is security work: enrolment instructions, authenticator coverage, recovery paths, access reviews, and the documentation people need before an incident. Strawberry can use the myOTP App pages, identity policy, and rollout materials you provide to prepare a deployment checklist and recovery guide review. It can also prepare an access-audit pack and a recurring security follow-up.
01
Make enrolment clear enough that support does not become the second factor.
Authenticator rollout succeeds when each person knows what they need, where help exists, and how completion is verified. Strawberry can organise the policy and rollout materials into a practical checklist for the specific cohort being enrolled.
02
Review recovery instructions before somebody is locked out under pressure.
Recovery guidance needs to protect the account without asking a stressed employee to guess the next step. Strawberry can examine the instructions you provide for missing verification, unsafe shortcuts, and unclear ownership. It does this before the document is needed in a real incident.
03
Give access review a list of people and facts, not a scavenger hunt.
An administrator should be able to see where a person’s status, team membership, and authenticator ownership disagree without relying on a manually assembled spreadsheet. Strawberry can prepare a review pack from the records and roster context you explicitly provide.
04
Check recovery and access changes on the calendar that matches security ownership.
A first-business-day review keeps recent account changes and recovery concerns visible before they become a quarterly surprise. The report should cover only the defined change window. The security owner can then act on current exceptions rather than reread the full estate.
It can work with the visible administrative context and related policy documents you choose, but do not include one-time codes or authenticator secrets.
No native myOTP App action is claimed here; an enrolment, reset, or access update must remain an independently reviewed security decision.
Yes. Save the allowed sources, exception rules, reporting period, and security owner as a skill, then schedule it around the access-governance cycle.
Keep authentication secrets outside the workflow entirely, minimise personal data, and check any proposed administrative move against the authoritative identity record.