Govern and administer the platform
Define identity, isolation, evidence, sovereignty, and delegated administration.
This path is for provider and tenant administrators, security owners, auditors, privacy teams, risk owners, and architecture reviewers.
Outcome
You can define the customer and team boundary, assign accountable administrators, review a use case, specify evidence, and verify that sovereignty and recovery requirements are operable.
1. Define the hierarchy
Read Core concepts and record the installation, tenant, team, user, service identity, application, data, and model involved. Do not approve a use case while its tenant or accountable owner is ambiguous.
2. Assign administrative responsibility
Administration and operations distinguishes provider, tenant, team, platform, and service responsibilities. Separate people who operate shared infrastructure from people who manage access inside a customer boundary.
3. Review identity and access
Use Security and compliance to review federation, authentication, service identities, least privilege, separation of duties, secrets, and periodic access attestation.
Test both the primary interface and secondary paths such as search, APIs, logs, analytics, exports, and support tools.
4. Verify isolation
BullSequana AI carries tenant and team boundaries into applications, data, models, workspaces, pipelines, artifacts, reporting, quotas, and operational access. Verify that the memberships and delegated roles match the intended customer structure. Multi-tenancy and tiered access in Data describes the workspace model.
5. Define required evidence
For each approved use case, identify the evidence needed to answer:
- who performed the action
- which tenant and team applied
- what data, model, application, and tool were involved
- which policy or approval governed the action
- where processing and storage occurred
- how evidence is exported and retained
Use Security and compliance and Foundation observability.
6. Validate sovereignty and recovery
Review jurisdiction, data residency, disconnected operation, software and model delivery, telemetry, licensing, administrative access, backup, and recovery. A sovereignty requirement is incomplete if the platform cannot be upgraded or recovered through approved channels.
Use Security and compliance, Harbor delivery, and Backup and disaster recovery.
You are done when
- every boundary and owner is explicit
- access decisions can be reviewed and revoked
- isolation is tested beyond the primary UI
- evidence requirements map to actual platform signals
- sovereignty requirements include delivery, operation, upgrade, and recovery
- exceptions have an accountable approver and expiry