The operator's companion to the rollout: set up recovery before a single seat, choose your isolation posture deliberately, and verify the governed profile holds only what it should.
Set up the Org Recovery Key first, with a threshold of at least two officers. Veridenti enforces no 1-of-1 recovery: a single admin can never unilaterally recover a work vault, and a single admin leaving can never strand one. Optionally turn on “require Org Recovery before enrollment” so no work vault is ever created before there's a quorum to recover it.
On corporate devices, the managed work profile is pushed through Chrome/Edge managed-profile policy so employees never hand-build it (available at rollout). BYOD keeps the guided two-profile setup today: a work profile for the org, a separate personal profile the company never touches.
Default is isolate. Flip to coexist knowing the trade.
| Mode | What you get | What you give up |
|---|---|---|
| Isolate (default) | Strictest audit, DLP, and legal-hold scope. Zero personal data on the governed profile — the EU-privacy guarantee holds. | Employees run a separate personal profile/account for personal use. |
| Coexist | Convenience for SMBs with no separate personal device; a personal vault is allowed on the managed profile, still zero-knowledge to the org. | You give up the “no personal data on the governed profile” claim (and the cleanest DPIA answer). |
If an enrolling profile already has personal logins, the employee gets a path to create their free personal account (funded by the bundled seat) and move them — no orphaned data, no lockout. The one-click inline flow arrives at rollout; until then, personal items are quarantined from the work vault and exportable.
Confirm the governed profile captures nothing on personal browsing or non-managed domains, check the Human-Risk Index baseline, and confirm audit events are streaming to your SIEM — before you widen the rollout.
Work vs Personal → · Deployment & rollout guide → · Book a security review →