Menu
Business guides

Ask clear questions about your business data.

Access controls, workspace separation and hosting arrangements are different things. Understand what is available before you decide what your business needs.

· 3 min read

A team lead guiding a colleague at a laptop while he reviews a paper checklist.

Put it into a real working day

Ask which people can see each kind of record, how access is removed, and which hosting arrangement is actually supplied. Get a specific answer before relying on a dedicated-database assumption.

Ask what a workspace boundary means

A company context can limit which records a user works with, but it is not the same thing as a separate physical database. Ask how the intended workflow enforces that boundary and what has been tested. Do not infer dedicated infrastructure simply from the word tenant or workspace.

Start with the people who need access

List the tasks each person performs and the information they need. Individual accounts and appropriately limited permissions are easier to review than a shared owner login. Check the actual view with the user when responsibilities change. A role name alone does not explain every available action.

Permissions and record scope

Give people the access their work needs.

  1. Team member
  2. Assigned role
  3. Permitted action
  4. Record scope
  5. Sensitive-field checks
  6. Authorised work
  7. Restricted records

Be specific about infrastructure requirements

If hosting location, backups, recovery arrangements or a dedicated database matter to your business, ask for a clear answer and the applicable written terms. Confirm any dedicated-database or data-residency requirement directly with the team. An unanswered requirement should stay on the evaluation list.

Understand what an audit trail can show

Recorded events can help you investigate an action by time, actor and target. They do not establish that every possible action was captured or that a security certification exists. Use the audit page as one source of evidence rather than treating a successful integrity message as a complete security assessment.

Include AI in the discussion

An AI request can include workspace context beyond the typed prompt. Review whether sending that information to the configured provider is appropriate. If it is not, use the normal manual workflow. Do not confuse your own provider key with a guarantee about provider retention or hosting location.

A practical checklist for your next working week

List your sensitive workflows and user roles. Separate access questions from hosting questions. Ask for confirmation of any essential requirement. Review AI data sharing before enabling it.

Related guides

Before your next review

  • Workspace separation and a dedicated database describe different arrangements.
  • Confirm hosting location and data-residency requirements directly.
  • Use individual accounts with appropriate permissions.
  • An audit check assesses recorded information; it is not a certification.
  • Include AI context sharing in a security review.

Choose your next step

Read the related task guide, or ask us a question about the workflow your business needs.