Expected outcome
The security conversation is grounded in the exact workflow and evidence the evaluation will use.
You can use this public guide without a Tempera account, product credential, or private workspace. Product access begins only after private onboarding.
Before you start
- The evaluation workflow and data boundary
- Owners for integration, review, and security questions
Steps
- 01
List the data involved
Identify page content, screenshots, browser state, trace fields, reviewer notes, and any sensitive values.
- 02
List the credentials involved
Identify who owns each credential, where it is stored, what it can do, and how it will be revoked.
- 03
Set review and retention needs
Agree who may review evidence, what must remain redacted, how long evidence is needed, and what must be exported or deleted.
- 04
Request the matching deployment information
Ask the Tempera onboarding team for the current architecture and control evidence that applies to the proposed hosted or private environment.
What success looks like
- A data-flow sketch for the selected workflow
- A credential owner and revocation plan
- A written review and retention boundary
- A list of unanswered questions for the onboarding team
If something is blocked
- If the workflow cannot be explained without broad platform claims, narrow it to the first browser session and trace.
- If a required control is not documented for the selected environment, treat it as an open evaluation item rather than an assumed capability.