Identity & least privilege
Role, organisation membership, assignment and purpose are checked on the server. Staff and external identities remain separate in the production architecture.
The current pilot already uses server-side access checks, durable D1/R2 storage, restricted review gates and suppressed public reports. The Microsoft production target strengthens identity, network, database and monitoring controls before public rollout.
Role, organisation membership, assignment and purpose are checked on the server. Staff and external identities remain separate in the production architecture.
Every organisation record is workspace-scoped. Production moves to tenant_id plus Azure SQL row-level security and automated cross-tenant tests.
Public, account-private, organisation-confidential, restricted and sanitised analytics have visibly different handling and publication rules.
Imports, partner updates, AI suggestions, aggregate promotion, public reports and sensitive exports require an authorised decision.
Only reviewed aggregates enter place reporting. Small groups are server-suppressed and source rows are never returned to public views.
Entra External ID, workforce Entra, Azure Front Door/WAF, API Management, Container Apps, Azure SQL, Blob, Service Bus and managed identities form the rollout target.
Safeguarding, children, health, identity documents and raw restricted cases are not sent to general AI. Other text is minimised and tokenised first.
Views, changes, exports, role changes and publication are auditable. Production targets tested backups, incident ownership and a UK regional recovery plan.
DPIA, controller/processor terms, ROPA and retention schedule approved
Entra tenant, MFA/Conditional Access and break-glass controls configured
Independent penetration and accessibility tests passed
Upload malware scanning, audit export and alerting operational
Backup restore and incident-response exercises evidenced
Organisation network access kept free; any future paid Aspire service separately approved and enabled