Deployment decision guide

Make authority, continuity, and data movement explicit before rollout.

A deployment decision should start with responsibility boundaries and protected data flows, then select infrastructure and providers around those constraints.

01

Where should operational authority live?

Keep identity verification, authoritative searches, watchlists, cases, evidence, occupancy, reporting, users, local audit, and regulated credentials inside IDSENTRA-CORE.

02

What belongs in the commercial control plane?

Customer/site commercial state, deployment identity, entitlements, signed licensing, release channels, activation, and privacy-minimized fleet health belong in IDSENTRA-DISTRO.

03

What can the public website receive?

Only approved business-evaluation information. It should never receive patron identity records, case/evidence payloads, provider credentials, license signing material, or operational PII.

04

How should temporary control-plane outages behave?

CORE should rely on locally verified signed state and bounded cached lease behavior according to deployment policy rather than becoming unavailable solely because DISTRO is temporarily unreachable.

05

How should providers be selected?

Choose providers behind explicit server-side contracts based on security, availability, legal/regulatory fit, geography, retention, support, and operational requirements rather than embedding provider brands into product architecture.

06

What must be validated before launch?

Roles, authoritative sources, site/device topology, data lifecycle, backup/recovery, provider credentials, release policy, abuse controls, legal notices, acceptance tests, support ownership, and production readiness.