University implementation checklist
Discovery
- [ ] Name the university data owner, technical owner, security contact, accessibility contact, and incident contact.
- [ ] Confirm user populations, expected athlete count, member count, storage, custom domain, retention period, and AI policy.
- [ ] Choose shared, dedicated, or self-hosted deployment and record data residency requirements.
- [ ] Identify the authoritative identity provider and approved email domains.
Security and privacy
- [ ] Execute the institution agreement and data-processing/FERPA schedule.
- [ ] Complete the current HECVAT requested by the institution with evidence links.
- [ ] Approve subprocessors and cross-border data handling.
- [ ] Verify encryption, backup, restore, logging, vulnerability-management, and incident-notification procedures.
- [ ] Set
guestAccessEnabled=falseand verify a customer hostname cannot enter the demo tenant. - [ ] Approve or disable AI assistance. Record provider terms when enabled.
Technical launch
- [ ] Provision tenant/infrastructure from the launch desk or reviewed manifest.
- [ ] Apply migrations, create private object storage, and require object storage in readiness checks.
- [ ] Verify DNS ownership and TLS before marking a custom domain verified.
- [ ] Configure identity and test owner, operator, reviewer, viewer, and athlete seats.
- [ ] Send an owner invitation and verify expiry, wrong-email refusal, and revocation.
- [ ] Test tenant isolation, exports, uploads/downloads, audit events, quotas, and rate limits.
- [ ] Verify
/api/healthand/api/readyfrom the production monitor.
Acceptance and operations
- [ ] Complete keyboard, screen-reader, zoom/reflow, contrast, and reduced-motion testing.
- [ ] Run a restore drill and document recovery time and recovery point achieved.
- [ ] Confirm support hours, severity definitions, escalation path, and maintenance window.
- [ ] Schedule retention preview and execution jobs with deletion evidence.
- [ ] Capture launch approval and a 30-day review date.
Next: operations SLA