The platform resolves the account and organization first.
Control map · Product path
See the checks around a protected change.
Enterprise control starts with the account, checks its role and app access, limits where the change may run, and keeps a record of the result.
The request identifies the app, record, and intended change.
The change continues only when the account has the required access.
The change stays inside the selected organization, app, and deployment.
One policy path, four control questions.
The page follows the same action from request to evidence instead of presenting identity, security, governance, and support as interchangeable feature cards.
Identity and access
Users, service accounts, directory connections, and role assignments establish the account.
Resolve before actionPolicy and approval
Role, resource, environment, and human-review requirements determine whether the change moves.
Hold when unclearDeployment boundary
Tenancy, network isolation, region, and secret access define the permitted target.
Constrain the runtimeEvidence and response
Caller, decision, change, result, and escalation route remain available in the owning service.
Keep the recordDeployment comparison
Choose the boundary that matches the operating model.
The product repositories support shared and dedicated deployment patterns. The actual boundary, ownership, service level, and compliance scope must be confirmed in the contract.
Certification coverage, availability commitments, recovery objectives, and response targets are confirmed in the applicable order form and service documentation.
Operations handoff
When a control fires, the owner is already named.
User, account, workflow, and deployment events can feed incident, change, release, and review work. The owning service determines which details are available.
- Incident
- Severity, impact, owner, response, follow-up
- Change
- Risk, approval, release window, rollback state
- Security
- Principal, event, policy result, export destination
- Review
- Open decisions, capacity, exceptions, roadmap owner
Map the identity before granting access.
Review roles, app boundaries, audit coverage, deployment ownership, and contract terms.