Complete the trust-center review¶
Security completion is recorded by a real in-product action. See Docs authority & product state.
Review trust-center controls, confirm the read-only connector boundary, and acknowledge the trust checklist.
Steps¶
Role: Security reviewer or Admin with trust-center access.
- Open the SaaS Trust Center. For self-hosted deployments, use the same path on your own instance host.
- Review the current SOC 2 status. SOC 2 is not yet held; use Compliance as the status authority.
- Review the penetration-test summary and status, architecture and data-flow diagrams, and the versioned subprocessor list.
- Confirm tenant isolation, the contracted residency lane, SSO and MFA policy, and read-only connector proof with positive-read and denied-write evidence.
- Complete the break-glass support access review. Confirm no standing access, denied or expired grant evidence, and that the residency lane fails closed.
- Record the reviewed artifact and control versions, then acknowledge the checklist in-product.
Success evidence¶
The trust checklist records the reviewer, artifact versions, control versions, connector boundary result, fail-closed evidence, and acknowledgment time.
Recovery¶
Do not acknowledge a control with missing fail-closed evidence. Return the failed control to its named owner, revoke or expire an uncertain support grant, and rerun the connector, grant, and residency checks before acknowledgment.