# Self-host responsibilities and acceptance

Source: https://codeherder.com/docs/self-host-responsibilities/

Who owns, operates and is told about credentials, devices, identity, backups and contacts on your install, plus the launch acceptance record to sign.

Your organization hosts CodeHerder in its own AWS account. Your instance operator runs the server. The instance operator creates the first account and becomes the bootstrap owner. Your support contact gives vendor-side support under your support agreement. CodeHerder staff have no access to your install.

Your organization can be its own instance operator. Your support agreement can also assign the instance operator role and the support contact role to one party. Write the names in the matrix below.

## Responsibility matrix

“Owns” means the party that answers for the item. “Operates” means the party that does the work. “Is told” means the party that hears first when the item changes or fails.

| Item | Owns | Operates | Is told |
| --- | --- | --- | --- |
| AI routes (Anthropic direct, Bedrock, gateway credentials) | Your organization | The instance operator on the server. The device owner on a device. | The instance operator |
| Git-host tokens (GitHub, GitLab) | Your organization | The instance operator for integrations. The device owner for device tokens. | The instance operator |
| The four at-rest keys: `CH_WEBHOOK_SECRET_KEY`, `CH_INTEGRATIONS_SECRET_KEY`, `CH_OTP_HMAC_KEY`, `CH_INTEGRATIONS_OAUTH_STATE_KEY` | Your organization. It keeps two offline copies held by two people. See [Escrow the four keys](https://codeherder.com/docs/self-host-backups/#escrow-the-four-keys-before-first-boot). | The instance operator | Your approving owner |
| The licence (`CH_LICENSE`) | Your organization, as holder | The instance operator installs and renews it. The support contact supplies the licence file. | Your approving owner. The instance operator before it expires. |
| Devices | Each device owner, the person who runs the device server | The device owner | The instance operator |
| Identity (the Cognito user pool in your account) | Your organization | Your identity administrator. The instance operator for the first account and `CH_INSTANCE_OPERATORS`. | The instance operator |
| Backups | Your organization | The instance operator | Your approving owner |
| Incident contacts | Your organization names the communication owner and the incident commander. | The incident commander runs the incident. The support contact handles product defects. | The communication owner and the instance operator |
| Acceptance evidence | The instance operator and your administrator, jointly | The instance operator | Your approving owner |

Choose an execution mode for each device: process mode or Docker mode. Process mode has no isolation. If you use it, your organization must accept that risk. See [Who can run code on your device](https://codeherder.com/docs/device-trust/). Device disk encryption is your organization’s choice. Record the choice for each device in the acceptance record.

For identity, see [Self-hosted Cognito sign-in](https://codeherder.com/docs/self-host-cognito/). For backups, see [Self-hosted backups](https://codeherder.com/docs/self-host-backups/). For incident contacts, see [Self-hosted support and incident response](https://codeherder.com/docs/self-host-support/).

## Launch acceptance record

Collect this evidence before live work starts. Leave each row blank until the evidence exists.

| Evidence | Where recorded | Date | Result |
| --- | --- | --- | --- |
| Identity setup and first account. See [Self-hosted acceptance journey](https://codeherder.com/docs/self-host-acceptance-journey/). |  |  |  |
| Cognito checks (SSO and SCIM permissions). See [Verify Cognito before go-live](https://codeherder.com/docs/self-host-cognito-verification/). |  |  |  |
| A completed workflow in each selected execution mode. See [Self-hosted acceptance journey](https://codeherder.com/docs/self-host-acceptance-journey/). |  |  |  |
| Administrator briefing acknowledged. See [Administrator briefing](https://codeherder.com/docs/self-host-admin-briefing/). |  |  |  |
| Paging test. See [Test the paging path](https://codeherder.com/docs/self-host-support/#test-the-paging-path). |  |  |  |
| Support bundle send test. See [Send the bundle](https://codeherder.com/docs/support-bundle/#send-the-bundle). |  |  |  |
| Four at-rest keys escrowed |  |  |  |
| Device disk encryption choice, for each device |  |  |  |
| Incident contacts: communication owner, incident commander, instance operator and the support contact’s address |  |  |  |

Sign the record when every row has a pass result. Do not start live customer work before both people sign.

| Sign-off | Name | Date | Signature |
| --- | --- | --- | --- |
| The instance operator |  |  |  |
| Your administrator |  |  |  |

## Rule text for approval

This text is a template. Adapt it to your policy.

> **Responsibility rule.**
>
> 1. The customer owns its AI routes, git-host tokens, at-rest keys and licence. The instance operator, ______, operates them on the server. Device owners operate device credentials.
> 2. Each device belongs to its device owner. The customer chooses device disk encryption.
> 3. The customer owns its identity pool. The customer’s identity administrator operates it. The instance operator creates the first account.
> 4. The customer owns its backups. The instance operator operates them.
> 5. The customer names its communication owner and its incident commander, ______. The support contact, ______, handles product defects.
> 6. The instance operator and the customer’s administrator sign the launch acceptance record before live work starts.

## Related guides

- [Self-hosted support and incident response](https://codeherder.com/docs/self-host-support/)
- [Self-hosted operator access and changes](https://codeherder.com/docs/self-host-operator-access/)
- [Self-hosted backups](https://codeherder.com/docs/self-host-backups/)
- [Self-hosted Cognito sign-in](https://codeherder.com/docs/self-host-cognito/)
- [Self-hosted support bundle](https://codeherder.com/docs/support-bundle/)
- [Self-hosted deployment](https://codeherder.com/docs/self-hosting/)
