Map data boundaries and shared responsibility
Trace what enters the workload, where it travels, what providers retain, who can access it, and what the team must delete or export.
Direct answer
A provider's security controls do not remove the venture's responsibility for data selection, access, application design, logging, user disclosure, retention choices, and incident response. Map the actual service and contract, not a generic cloud diagram.
Decision sequence
- Classify the permitted and prohibited input categories for the workload.
- Trace prompts, retrieved context, tool calls, outputs, logs, caches, backups, and support access.
- Verify service-specific training, retention, regional, encryption, deletion, and subcontractor terms.
- Test access removal, deletion, export, and incident procedures before production use.
Evidence to keep
- A current data-flow diagram.
- A service-specific responsibility matrix.
- Retention and deletion tests.
- Approved input rules visible to users and operators.
Sources and interpretation boundaries
Microsoft LearnAI shared responsibility modelHow customer and provider responsibilities change across SaaS, PaaS, and IaaS approaches.National Institute of Standards and TechnologyGenerative AI Profile, NIST AI 600-1Generative-AI risks and suggested actions across the AI lifecycle.National Institute of Standards and TechnologySecure Software Development FrameworkOutcome-based secure software practices for preparing, protecting, producing, and responding.
Decision boundary
This guide is an original educational synthesis. It does not inspect your workload, validate a contract, test a provider, certify security, recommend an investment, or promise cost, performance, funding, revenue, savings, or growth.