Put it into a real working day
Ask which people can see each kind of record, how access is removed, and which hosting arrangement is actually supplied. Get a specific answer before relying on a dedicated-database assumption.
Ask what a workspace boundary means
A company context can limit which records a user works with, but it is not the same thing as a separate physical database. Ask how the intended workflow enforces that boundary and what has been tested. Do not infer dedicated infrastructure simply from the word tenant or workspace.
Start with the people who need access
List the tasks each person performs and the information they need. Individual accounts and appropriately limited permissions are easier to review than a shared owner login. Check the actual view with the user when responsibilities change. A role name alone does not explain every available action.
Permissions and record scope
Give people the access their work needs.
-
Team member
- Assign deliberately Assigned role
-
Assigned role
- Check permission Permitted action
-
Permitted action
- Limit records Record scope
-
Record scope
- Protect fields Sensitive-field checks
-
Sensitive-field checks
- Within granted access Authorised work
- Outside visible result Restricted records
- Authorised work
- Restricted records
Be specific about infrastructure requirements
If hosting location, backups, recovery arrangements or a dedicated database matter to your business, ask for a clear answer and the applicable written terms. Confirm any dedicated-database or data-residency requirement directly with the team. An unanswered requirement should stay on the evaluation list.
Understand what an audit trail can show
Recorded events can help you investigate an action by time, actor and target. They do not establish that every possible action was captured or that a security certification exists. Use the audit page as one source of evidence rather than treating a successful integrity message as a complete security assessment.
Include AI in the discussion
An AI request can include workspace context beyond the typed prompt. Review whether sending that information to the configured provider is appropriate. If it is not, use the normal manual workflow. Do not confuse your own provider key with a guarantee about provider retention or hosting location.
A practical checklist for your next working week
List your sensitive workflows and user roles. Separate access questions from hosting questions. Ask for confirmation of any essential requirement. Review AI data sharing before enabling it.
Related guides
Before your next review
- Workspace separation and a dedicated database describe different arrangements.
- Confirm hosting location and data-residency requirements directly.
- Use individual accounts with appropriate permissions.
- An audit check assesses recorded information; it is not a certification.
- Include AI context sharing in a security review.
Choose your next step
Read the related task guide, or ask us a question about the workflow your business needs.