I think it’s important that United IT be aware of incidents whereby a user has unauthorized/unintended access to another users private data.
In cases where CS might try to brush it off and simply say that you should just delete the email, I would make sure a report is filed with IT. That CS approach is a disservice to UA and themselves. Escalate if needed. These incidents can *potentially* hurt UA in a SOC 2 audit.
And if UA is not SOC 2 compliant right now, then I might rethink my choice to have given them more private data.