Deployment hardening

Deploy it right the first time.

The operator's companion to the rollout: set up recovery before a single seat, choose your isolation posture deliberately, and verify the governed profile holds only what it should.

Step 1 · Before you enroll a single seat

01Configure Org Recovery — with at least two officers.Shipped

Set up the Org Recovery Key first, with a threshold of at least two officers. Veridenti enforces no 1-of-1 recovery: a single admin can never unilaterally recover a work vault, and a single admin leaving can never strand one. Optionally turn on “require Org Recovery before enrollment” so no work vault is ever created before there's a quorum to recover it.

Step 2 · Provision the work profile

02Push the managed work profile.MDM auto-provision at rollout

On corporate devices, the managed work profile is pushed through Chrome/Edge managed-profile policy so employees never hand-build it (available at rollout). BYOD keeps the guided two-profile setup today: a work profile for the org, a separate personal profile the company never touches.

Step 3 · Set your posture

03Choose isolate vs coexist — deliberately.Shipped

Default is isolate. Flip to coexist knowing the trade.

ModeWhat you getWhat you give up
Isolate (default)Strictest audit, DLP, and legal-hold scope. Zero personal data on the governed profile — the EU-privacy guarantee holds.Employees run a separate personal profile/account for personal use.
CoexistConvenience for SMBs with no separate personal device; a personal vault is allowed on the managed profile, still zero-knowledge to the org.You give up the “no personal data on the governed profile” claim (and the cleanest DPIA answer).
Step 4 · Bring existing data across

04Migration never dead-ends.One-click flow at rollout

If an enrolling profile already has personal logins, the employee gets a path to create their free personal account (funded by the bundled seat) and move them — no orphaned data, no lockout. The one-click inline flow arrives at rollout; until then, personal items are quarantined from the work vault and exportable.

Step 5 · Lifecycle

05Offboarding runbook.Shipped

  1. Revoke the departing member's work-profile access (sessions die immediately).
  2. Retain the work vault through the Org Recovery Key quorum — audited end to end. A lone work vault is retained, not stranded.
  3. If the person was a recovery share-holder, re-run recovery setup to re-split the quorum — the console flags this on offboard.
  4. Their personal account lives elsewhere and was never yours to touch — it's untouched.
  5. The bundled personal entitlement converts to a self-serve plan so they keep their own data.
Step 6 · Confirm before you widen

06Verify the posture.Shipped

Confirm the governed profile captures nothing on personal browsing or non-managed domains, check the Human-Risk Index baseline, and confirm audit events are streaming to your SIEM — before you widen the rollout.

Next

Read the governance model, or bring your team.

Work vs Personal →  ·  Deployment & rollout guide →  ·  Book a security review →