CodeHerderSearch⌘KRequest access →

Self-host responsibilities and acceptance

Who owns, operates and is told about credentials, devices, identity, backups and contacts on your install, plus the launch acceptance record to sign.

Your organization hosts CodeHerder in its own AWS account. Your instance operator runs the server. The instance operator creates the first account and becomes the bootstrap owner. Your support contact gives vendor-side support under your support agreement. CodeHerder staff have no access to your install.

Your organization can be its own instance operator. Your support agreement can also assign the instance operator role and the support contact role to one party. Write the names in the matrix below.

Responsibility matrix

“Owns” means the party that answers for the item. “Operates” means the party that does the work. “Is told” means the party that hears first when the item changes or fails.

Item Owns Operates Is told
AI routes (Anthropic direct, Bedrock, gateway credentials) Your organization The instance operator on the server. The device owner on a device. The instance operator
Git-host tokens (GitHub, GitLab) Your organization The instance operator for integrations. The device owner for device tokens. The instance operator
The four at-rest keys: CH_WEBHOOK_SECRET_KEY, CH_INTEGRATIONS_SECRET_KEY, CH_OTP_HMAC_KEY, CH_INTEGRATIONS_OAUTH_STATE_KEY Your organization. It keeps two offline copies held by two people. See Escrow the four keys. The instance operator Your approving owner
The licence (CH_LICENSE) Your organization, as holder The instance operator installs and renews it. The support contact supplies the licence file. Your approving owner. The instance operator before it expires.
Devices Each device owner, the person who runs the device server The device owner The instance operator
Identity (the Cognito user pool in your account) Your organization Your identity administrator. The instance operator for the first account and CH_INSTANCE_OPERATORS. The instance operator
Backups Your organization The instance operator Your approving owner
Incident contacts Your organization names the communication owner and the incident commander. The incident commander runs the incident. The support contact handles product defects. The communication owner and the instance operator
Acceptance evidence The instance operator and your administrator, jointly The instance operator Your approving owner

Choose an execution mode for each device: process mode or Docker mode. Process mode has no isolation. If you use it, your organization must accept that risk. See Who can run code on your device. Device disk encryption is your organization’s choice. Record the choice for each device in the acceptance record.

For identity, see Self-hosted Cognito sign-in. For backups, see Self-hosted backups. For incident contacts, see Self-hosted support and incident response.

Launch acceptance record

Collect this evidence before live work starts. Leave each row blank until the evidence exists.

Evidence Where recorded Date Result
Identity setup and first account. See Self-hosted acceptance journey.
Cognito checks (SSO and SCIM permissions). See Verify Cognito before go-live.
A completed workflow in each selected execution mode. See Self-hosted acceptance journey.
Administrator briefing acknowledged. See Administrator briefing.
Paging test. See Test the paging path.
Support bundle send test. See Send the bundle.
Four at-rest keys escrowed
Device disk encryption choice, for each device
Incident contacts: communication owner, incident commander, instance operator and the support contact’s address

Sign the record when every row has a pass result. Do not start live customer work before both people sign.

Sign-off Name Date Signature
The instance operator
Your administrator

Rule text for approval

This text is a template. Adapt it to your policy.

Responsibility rule.

  1. The customer owns its AI routes, git-host tokens, at-rest keys and licence. The instance operator, ______, operates them on the server. Device owners operate device credentials.
  2. Each device belongs to its device owner. The customer chooses device disk encryption.
  3. The customer owns its identity pool. The customer’s identity administrator operates it. The instance operator creates the first account.
  4. The customer owns its backups. The instance operator operates them.
  5. The customer names its communication owner and its incident commander, ______. The support contact, ______, handles product defects.
  6. The instance operator and the customer’s administrator sign the launch acceptance record before live work starts.

Last updated

CodeHerder

Round up your herd.

Bring every human and every agent onto one table. Watch the work move. Costs update as it happens.

Try "pricing", "connect a device", or "who reviews the code"

↑↓ move · ↵ open · esc close