Where should operational authority live?
Keep identity verification, authoritative searches, watchlists, cases, evidence, occupancy, reporting, users, local audit, and regulated credentials inside IDSENTRA-CORE.
A deployment decision should start with responsibility boundaries and protected data flows, then select infrastructure and providers around those constraints.
Keep identity verification, authoritative searches, watchlists, cases, evidence, occupancy, reporting, users, local audit, and regulated credentials inside IDSENTRA-CORE.
Customer/site commercial state, deployment identity, entitlements, signed licensing, release channels, activation, and privacy-minimized fleet health belong in IDSENTRA-DISTRO.
Only approved business-evaluation information. It should never receive patron identity records, case/evidence payloads, provider credentials, license signing material, or operational PII.
CORE should rely on locally verified signed state and bounded cached lease behavior according to deployment policy rather than becoming unavailable solely because DISTRO is temporarily unreachable.
Choose providers behind explicit server-side contracts based on security, availability, legal/regulatory fit, geography, retention, support, and operational requirements rather than embedding provider brands into product architecture.
Roles, authoritative sources, site/device topology, data lifecycle, backup/recovery, provider credentials, release policy, abuse controls, legal notices, acceptance tests, support ownership, and production readiness.