Guardian Services
02
Guardian engagement process
Authorize Scope and Access
No customer environment should be accessed on assumption. Authorization establishes ownership, boundaries, credentials, timing and permitted actions before technical work begins.
Customer actions
What you do
- Confirm authority over the environment
- Approve the server, database, domains and service window
- Provide temporary access through the agreed method
- Identify restricted data, business hours and communication contacts
DPIO actions
What DPIO does
- Document the agreed scope
- Request only the access needed for the service
- Confirm whether the engagement is observational or change-authorized
- Establish credential rotation or revocation expectations