PARTNERS

Add selected Workbench capabilities through bounded OEM and partner integrations

Deliverablesdeliverable
deliverable

Enterprise Deployment Figures

Canonical figures for enterprise SecEng deployment and operating models.

Public sample
Client deliverable
public-sample
System
Enterprise Deployment Figures
Environment
Production pilot

# Enterprise Deployment Figures

ENT-01

Enterprise Operating Model

AppSec, platform, product, data, governance, and engineering teams need explicit ownership across the AI security lifecycle.

Operating model assigning mapping, testing, control, evidence, and decision responsibilities across AppSec, platform, product, data, governance, and engineering teams.

Shared Foundation
  • AppSec and Security
    • Own threat and evidence interpretation
    • Prioritize qualified risk
    • Define security acceptance criteria
  • AI and Platform
    • Own shared model, retrieval, tool, and identity controls
    • Provide shared telemetry and policy hooks
  • Product
    • Own user and workflow behavior
    • Approve product tradeoffs and launch conditions
  • Data and Privacy
    • Own data, tenant, retention, and provenance boundaries
    • Approve sensitive-data use and external sinks
ENT-02

Deployment Control Spectrum

Hosted, local-worker, sidecar, and air-gapped models trade operating simplicity for customer control and isolation.

Four deployment models ordered from hosted service through local worker and embedded sidecar to private or air-gapped deployment.

LOWERHIGHERHosted serviceFastest operating path with theleast customer-managedinfrastructure.Customer-local workerSensitive execution remains withinthe customer environment whilecontrol-plane services remainhosted.Embedded sidecarCapability runs inside a customeror partner workflow with tighterlocal control.Private or air-gappeddeploymentMaximum environment isolation withthe highest customer operatingresponsibility.DECISION DIMENSIONSCustomer control increasesEnvironment isolation increasesCustomer operatingresponsibility increasesIntegration and supportcomplexity increasesAVAILABILITY BOUNDARYCurrent, pilot, and planned models remaindistinctSupport and evidence ownership vary by model
ENT-03

Enterprise Evidence Package

Enterprise delivery should preserve machine-readable findings, retest records, control evidence, and executive reporting in one traceable stack.

Layered enterprise evidence package from technical evidence through findings, remediation and retest records, governance mapping, and executive reporting.

PROVENANCETechnical evidenceRuntime, scan, and test evidenceConfiguration, policy, and permission snapshotsReproduction recordsFindings and pathsMachine-readable findingsEvidence-qualified pathsClaim and validation stateRemediation and retestControl and owner recordRetest and residual-risk resultRegression fixtures when includedGovernance and program evidenceControl and framework mapping when includedDecision and exception recordsVersion and review historyDecision-ready reportingTechnical reportExecutive summaryProgram and portfolio view when includedCONSUMERSEngineering andplatformSecurity andgovernanceLeadership and riskowners