TechnoMile Responsibility Matrices: Detailed
| Functional Area | TechnoMile's Role | Customer's Role |
|---|---|---|
| Access & authentication setup | Owns identity infrastructure, MFA enforcement, session controls, and authentication mechanisms platform-wide | None at the control level (customers federating via SSO/SAML still configure their own IdP — a configuration choice, not an assigned obligation) |
| User & account management | Manages account lifecycle for OAuth-based users; provides the account framework, audit support, and inactivity/expiration enforcement mechanisms | For SSO/SAML-integrated organizations: creates, modifies, reviews, and disables accounts in their own IdP; defines roles/conditions of use for their users |
| Application security configuration | Owns secure baseline configuration, change control, and configuration monitoring | None at the control level |
| Data handling & CUI controls | Owns the technical safeguards: encryption, boundary protection, and the system's capability to enforce access restrictions | Determines what data constitutes CUI, properly marks/labels it, and restricts which of their own users can access it (e.g., field- and record-level access configuration). TechnoMile's system can't make this determination on the customer's behalf. |
| Audit & monitoring | Owns audit log generation, retention, protection, and review processes | None at the control level |
| Incident response | Owns incident detection, handling, and reporting for the platform | Reasonable expectation to report suspected issues involving their own users — standard practice, not a formally assigned control |
| Vulnerability & risk management | Owns vulnerability scanning, flaw remediation, and risk assessment | None at the control level |
| Security awareness & training | Owns and documents the security awareness/training program that satisfies the control | Best practice for customers to train their own end users — not an assigned control |
| Personnel security | Owns screening, vetting, and personnel security processes for TechnoMile staff/contractors with system access | None at the control level |
| Platform deployment & maintenance | Owns hosting, deployment, maintenance, physical security (via AWS), and assessment/authorization activities | None at the control level |
| Functional Area | TechnoMile's Role | Customer's Role |
|---|---|---|
| Access & authentication setup | Builds application-layer authentication on top of identity controls inherited from Salesforce Government Cloud Plus | Customers federating via SSO/SAML configured through their own IdP |
| User & account management | Provides the account framework within the application; supports role-based access control | Creates, modifies, reviews, and disables their own users' accounts and roles, typically through their Salesforce org or federated IdP |
| Application security configuration | Owns TechnoMile application code, secure configuration, and change control on top of the Salesforce Government Cloud Plus | None at the control level |
| Data handling & CUI controls | Owns data/CUI-handling technical safeguards built into the TechnoMile application; inherits encryption and boundary protection from the Salesforce Government Cloud Plus environment | Determines what data constitutes CUI, properly marks/labels it, and restricts which of their own users can access it within the application (e.g., field- and record-level access configuration). Neither TechnoMile nor the underlying platform can make this determination on the customer's behalf. |
| Audit & monitoring | None at the control level | Customer is responsible for auditing and monitoring CRM data and account activity within their environment |
| Incident response | Owns incident handling for the TechnoMile application | Reasonable expectation to report suspected issues involving their own users — standard practice |
| Vulnerability & risk management | Owns vulnerability management for the TechnoMile application | None at the control level |
| Security awareness & training | Owns TechnoMile's internal training program | Best practice for customers to train their own end users |
| Personnel security | None at the control level | Owns screening and vetting for internal personnel with system access |
| Platform deployment & maintenance | Owns application deployment and maintenance; hosting, physical security, and infrastructure maintenance are inherited from Salesforce Government Cloud Plus | None at the control level |
| Functional Area | TechnoMile's Role | Customer's Role |
|---|---|---|
| Access & authentication setup | Builds application-layer authentication on top of identity controls inherited from Microsoft Azure Government | Customers federating via SSO/SAML configured through their own IdP |
| User & account management | Provides the account framework within the application; supports role-based access control. | Creates, modifies, reviews, and disables their own users' accounts and roles, typically through their M365 tenant or federated IdP |
| Application security configuration | Owns TechnoMile application code, secure configuration, and change control on top of the Microsoft Azure Government | None at the control level |
| Data handling & CUI controls | Owns data/CUI-handling technical safeguards built into the TechnoMile application; inherits encryption and boundary protection from the Microsoft Azure Government environment | Determines what data constitutes CUI, properly marks/labels it, and restricts which of their own users can access it within the application (e.g., field- and record-level access configuration). Neither TechnoMile nor the underlying platform can make this determination on the customer's behalf. |
| Audit & monitoring | None at the control level. | Customer is responsible for auditing and monitoring CRM data and account activity within their environment |
| Incident response | Owns incident handling for the TechnoMile application | Reasonable expectation to report suspected issues involving their own users — standard practice |
| Vulnerability & risk management | Owns vulnerability management for the TechnoMile application. | None at the control level |
| Security awareness & training | Owns TechnoMile's internal training program. | Best practice for customers to train their own end users |
| Personnel security | None at the control level. | Owns screening and vetting for internal personnel with system access |
| Platform application deployment & maintenance | Owns application deployment and maintenance; hosting, physical security, and infrastructure maintenance are inherited from Microsoft Azure Government | None at the control level |