{
 "slug": "insider-completable-operations",
 "topic_id": "TOPIC-152",
 "cluster": "Telecom Carrier & Subscriber Identity",
 "tier": "Tier A",
 "title": "The bribed rep problem: a taxonomy of insider-completable operations",
 "summary": "Retail and care staff need broad account authority to do their jobs. That authority includes exactly the operations an attacker wants. Monitoring detects the pattern afterwards; nothing prevents the individual transaction.",
 "lede": "Classify every high-consequence operation in your account management stack by one question: can a single employee complete it alone? The answer produces a list, and the list is your actual insider exposure.",
 "date": "2025-10-25",
 "category": "Definitional",
 "author_id": "nadia-ferreira-strand",
 "tags": [
  "insider threat",
  "telecom fraud",
  "retail channel",
  "account takeover",
  "dealer channel",
  "access control"
 ],
 "image_title": "Insider Completable Operations",
 "schema": "Article",
 "key_takeaways": [
  "Every control implemented inside carrier systems can be exercised by someone with the role. Only a factor held outside the carrier is beyond an insider's reach.",
  "The taxonomy has three classes: single-employee completable, two-employee completable, and not completable without the subscriber.",
  "The goal is not to eliminate class one but to move a small, named set of operations into class three."
 ],
 "body": [
  {
   "type": "h2",
   "text": "Prerequisites"
  },
  {
   "type": "diagram",
   "kind": "flow",
   "alt": "The taxonomy nobody has written down",
   "caption": "The exercise is listing them. Most organisations have never done it.",
   "nodes": [
    {
     "label": "Representative needs broad authority",
     "note": "to do the job"
    },
    {
     "label": "Authority includes high-consequence operations",
     "note": "unenumerated",
     "bad": true
    },
    {
     "label": "Single representative completes one alone",
     "note": "no second party",
     "bad": true
    },
    {
     "label": "Monitoring detects the pattern",
     "note": "after several",
     "bad": true
    }
   ]
  },
  {
   "type": "ul",
   "items": [
    "A list of every operation available in your care and retail account management tools — from the tool, not from a policy document.",
    "Role definitions and the count of employees and dealer staff holding each.",
    "Your fraud team's list of operations that have appeared in insider cases, internally or in public prosecutions."
   ]
  },
  {
   "type": "h2",
   "text": "Step 1 — Enumerate operations, not permissions"
  },
  {
   "type": "p",
   "html": "Start from what a rep can do, not from what a role grants. Permissions are abstractions; operations are what appears in a fraud."
  },
  {
   "type": "p",
   "html": "Typical high-consequence set: SIM or eSIM profile change, port-out authorisation, account PIN reset, authorised-user addition, device upgrade with financing, plan change affecting billing, address change, payment method change, port freeze removal, account transfer of responsibility."
  },
  {
   "type": "h2",
   "text": "Step 2 — Assign each to a class"
  },
  {
   "type": "table",
   "caption": "Classification. Test by attempting the operation in a non-production environment with a single account rather than by reading documentation.",
   "head": [
    "Class",
    "Definition",
    "Insider exposure"
   ],
   "rows": [
    [
     "1",
     "One employee can complete it alone",
     "Full. Monitoring is the only control."
    ],
    [
     "2",
     "Requires two employees",
     "Reduced. Collusion required."
    ],
    [
     "3",
     "Cannot be completed without a subscriber-held factor",
     "Eliminated for the insider path."
    ]
   ]
  },
  {
   "type": "p",
   "html": "Be rigorous about class 2. If the second approval can be obtained by asking a colleague who approves without looking, the operation is functionally class 1. Test it."
  },
  {
   "type": "h2",
   "text": "Step 3 — Rank by downstream consequence"
  },
  {
   "type": "p",
   "html": "Not all class 1 operations matter equally. Rank by what an attacker gains."
  },
  {
   "type": "ol",
   "items": [
    "eSIM profile change — grants control of the number, which grants recovery on downstream accounts. Highest.",
    "Port-out authorisation — same outcome, different mechanism.",
    "Account PIN reset — enables the two above through the front door.",
    "Payment method change — direct financial fraud, lower downstream leverage.",
    "Address change — enables device shipment fraud and mail interception.",
    "Authorised user addition — persistent access, often the longest-lived."
   ]
  },
  {
   "type": "h2",
   "text": "Step 4 — Move the top three to class 3"
  },
  {
   "type": "p",
   "html": "This is the entire recommendation. Not every operation, not most operations — three."
  },
  {
   "type": "p",
   "html": "Moving an operation to class 3 means it requires a fresh assertion from a credential the subscriber holds. No role, no override, no supervisor can substitute for it, because the factor does not exist inside the carrier's systems."
  },
  {
   "type": "h2",
   "text": "Step 5 — Design the override before you need it"
  },
  {
   "type": "p",
   "html": "A class 3 operation with no override strands subscribers whose devices are lost. An override that any rep can invoke returns the operation to class 1. The resolution is an override that is available, slow, attributable and rare."
  },
  {
   "type": "ul",
   "items": [
    "Performed by a named supervisor, signing a canonical statement of the basis.",
    "Subject to a delay measured in hours, not seconds.",
    "Notified to every enrolled authenticator and to the account's contact addresses.",
    "Reported weekly by store and by agent, because concentration is the signal."
   ]
  },
  {
   "type": "h2",
   "text": "Step 6 — Extend to the dealer channel"
  },
  {
   "type": "p",
   "html": "Authorised dealers and third-party retail are where this analysis usually finds its worst numbers, because the staff are not carrier employees, turnover is high, and the carrier's background screening does not reach them."
  },
  {
   "type": "p",
   "html": "A class 3 operation is indifferent to employment status, which is the property that makes this approach workable across a channel the carrier does not directly control."
  },
  {
   "type": "h2",
   "text": "Failure traps"
  },
  {
   "type": "ol",
   "items": [
    "Do not classify from documentation. Documentation describes intent; test the system.",
    "Do not treat supervisor approval as class 2 until you have measured how often supervisors decline.",
    "Do not move more than a handful of operations to class 3 in the first phase. Every one generates support volume while enrolment builds.",
    "Do not stigmatise staff. The overwhelming majority are honest, the taxonomy is about system design, and framing it otherwise will lose you the frontline cooperation you need."
   ]
  },
  {
   "type": "h2",
   "text": "A taxonomy of insider-completable operations"
  },
  {
   "type": "table",
   "caption": "Four classes worth enumerating",
   "head": [
    "Class",
    "Examples",
    "Second party today?"
   ],
   "rows": [
    [
     "Identity change",
     "SIM swap, port authorisation, recovery contact",
     "No"
    ],
    [
     "Contact change",
     "Address, email, phone of record",
     "No"
    ],
    [
     "Financial",
     "Credit, refund, plan change with a balance effect",
     "Sometimes above a threshold"
    ],
    [
     "Access",
     "Password reset, account unlock, profile merge",
     "No"
    ]
   ]
  },
  {
   "type": "p",
   "html": "Writing this list is the work. Once it exists, the question of which entries warrant a second party or a customer signature answers itself, and it is usually a short list at the top."
  },
  {
   "type": "h2",
   "text": "Objections and honest limits"
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“We monitor for unusual representative behaviour.”</strong> Which catches volume and pattern after several events. A bribed representative performing one high-value operation produces no pattern."
  },
  {
   "type": "p",
   "html": "<strong style=\"font-weight:600\">“Requiring a second party would halve our throughput.”</strong> On the whole queue, yes. On the four or five operations at the top of the list, it is a rounding error — which is why the enumeration matters more than the control."
  }
 ],
 "faq": [
  {
   "q": "Is this not just least privilege?",
   "a": "Least privilege reduces who can perform an operation. This taxonomy asks whether anyone inside the organisation can complete it at all, which is a different and stronger question."
  },
  {
   "q": "How do we handle subscribers who have not enrolled?",
   "a": "They remain on the current path until enrolled. Enrolment builds over months through natural touchpoints, and the control's value rises with coverage."
  },
  {
   "q": "What about accounts with multiple authorised users?",
   "a": "Decide explicitly whose credential governs which operations, and record it. Most carriers have never made that decision formally."
  },
  {
   "q": "Does this apply to business accounts?",
   "a": "Yes, and the delegation model fits well: an account administrator delegates specific operations to named individuals with expiry."
  },
  {
   "q": "Why doesn't least privilege solve this?",
   "a": "Because the representative legitimately needs the authority. The operations an attacker wants are inside the job."
  },
  {
   "q": "Why doesn't monitoring solve it?",
   "a": "It detects volume and pattern. A bribed representative performing one high-value operation produces neither."
  },
  {
   "q": "What is the actual work?",
   "a": "Enumerating the operations a single representative can complete alone. Most organisations have never written that list."
  }
 ],
 "sources": [
  {
   "t": "FCC — protecting consumers from SIM swap and port-out fraud",
   "u": "https://www.fcc.gov/sim-swap-port-out-fraud"
  },
  {
   "t": "FCC rules and regulations",
   "u": "https://www.fcc.gov/general/rules-regulations-title-47"
  },
  {
   "t": "Telecom fraud management practice literature on retail and dealer channel risk."
  },
  {
   "t": "GSMA — fraud and security resources",
   "u": "https://www.gsma.com/solutions-and-impact/technologies/security/"
  },
  {
   "t": "CISA — cybersecurity advisories",
   "u": "https://www.cisa.gov/news-events/cybersecurity-advisories"
  }
 ],
 "related": [
  {
   "slug": "line-change-authorization",
   "title": "The subscriber never signs",
   "category": "Vertical"
  },
  {
   "slug": "consequence-tiered-attributes",
   "title": "Emergency services and consequence tiering",
   "category": "Definitional"
  },
  {
   "slug": "carrier-as-authorization-party",
   "title": "Selling the number as a trust signal",
   "category": "Vertical"
  }
 ],
 "image": "https://cdn.twc.sh/images/igcache/Insider%20Completable%20Operations/1500_900/blog.jpg",
 "wordcount": 917,
 "url": "/blog/insider-completable-operations.html",
 "reading_time": "4 min read",
 "seo_title": "A taxonomy of insider-completable operations",
 "meta_description": "Retail and care staff need broad account authority to work. That authority includes exactly the operations an attacker wants performed.",
 "hub": {
  "slug": "topics/telecom-identity",
  "title": "Telecom and subscriber identity"
 },
 "answer": "More than most organisations have ever enumerated. Retail and care staff need broad account authority to do their jobs, and that authority includes exactly the operations an attacker wants: SIM changes, address updates, recovery contact changes and plan modifications. Monitoring finds the pattern after the fact.",
 "answer_q": "Which operations can a single support representative complete alone?",
 "glossary": [
  {
   "term": "Insider-completable",
   "def": "An operation a single authorised staff member can carry out with no second party."
  },
  {
   "term": "Bribed representative",
   "def": "An authorised user performing authorised actions for an attacker — the case least-privilege cannot address."
  },
  {
   "term": "Customer signature",
   "def": "An authorisation from the account holder, which is the only factor an insider cannot supply."
  }
 ],
 "checklist": {
  "title": "Building the taxonomy",
  "id": "taxonomy",
  "desc": "Four steps.",
  "steps": [
   {
    "name": "List every operation a single representative can complete.",
    "text": "From the permission model, not from the training manual."
   },
   {
    "name": "Score each by what it enables for an attacker.",
    "text": "Not by how often it is used."
   },
   {
    "name": "Require a customer signature on the top entries.",
    "text": "The customer is the one party the insider cannot impersonate."
   },
   {
    "name": "Leave the rest alone.",
    "text": "Throughput matters, and most of the queue is harmless."
   }
  ]
 },
 "cta": {
  "title": "Where this fits in Manav",
  "html": "Manav puts the authorising party back in the loop for the changes that matter, with a signature bound to the specific change and verifiable by a counterparty without calling you.",
  "href": "../docs.html",
  "label": "See change authorisation"
 }
}