Deployment topology
Identify which account and network hold the Workbench, workloads, management services, model endpoints, storage, telemetry, and evidence. Do not reuse a BYOC answer for a managed environment.
Security architecture
The Calliope AI security model depends on topology. BYOC, managed, on-premises, and air-gapped environments have different boundaries and operator responsibilities. The architecture should make those differences visible.
Identify which account and network hold the Workbench, workloads, management services, model endpoints, storage, telemetry, and evidence. Do not reuse a BYOC answer for a managed environment.
Define user ingress, administrative access, private connectivity, model egress, data-source routes, update channels, and any support path. Apply customer network policy around the customer-owned environment.
Use container and workspace boundaries, resource limits, storage scoping, and separate identities appropriate to the selected platform. Validate the controls against the workload rather than assuming one universal tenancy model.
Connect SSO through SAML or OIDC, assign RBAC, and inventory user, administrator, service, support, and model-provider credentials. Review privilege by role and topology.
Astrolift AI owns platform runtime concerns. Zentinelle AI owns agent-level observability and policy. Both are separate products from Workbench and should appear explicitly when included in the design.
Define patching, backup, incident response, access records, runtime telemetry, policy evidence, retention, and escalation ownership. The purchased support scope should name which responsibilities belong to Calliope AI.
Stop choosing between moving fast and staying in control.
See how it works →