IDSENTRA Enterprise Evaluation Checklist Version: 2026-08-29 1. Workflow fit [ ] Identity verification workflow mapped [ ] Watchlist screening sources mapped [ ] Alert escalation and response ownership defined [ ] Investigation/case handoff defined [ ] Evidence handling and review requirements defined [ ] Responsible-gaming/self-exclusion workflows mapped where applicable [ ] Reporting and audit requirements defined 2. Authority and data boundaries [ ] Public website treated as a low-trust surface [ ] IDSENTRA-CORE operational authority documented [ ] IDSENTRA-DISTRO commercial authority documented [ ] Patron/case/operational PII excluded from DISTRO telemetry [ ] Regulated-source credentials remain server-side [ ] Data retention and deletion responsibilities assigned 3. Identity and access [ ] User roles and permissions mapped [ ] Privileged administrative roles limited [ ] Session and password policies reviewed [ ] User lifecycle ownership defined [ ] Audit expectations for privileged actions defined 4. Deployment and continuity [ ] Hosting topology selected [ ] PostgreSQL ownership and backup policy defined [ ] Release channel policy defined [ ] Signed licensing/entitlement continuity reviewed [ ] Control-plane outage behavior accepted [ ] Recovery objectives and restore testing defined 5. Integrations [ ] Authoritative sources inventoried [ ] Identity inputs inventoried [ ] Enterprise identity/directory requirements identified [ ] Notification/reporting destinations identified [ ] Provider-specific terms, credentials, and validation requirements reviewed 6. Security and compliance [ ] Applicable regulatory obligations identified [ ] Privacy requirements mapped [ ] Retention requirements mapped [ ] Incident-response ownership defined [ ] Security evidence reviewed against implemented controls [ ] No unsupported certification or regulatory claims assumed 7. Implementation and acceptance [ ] Pilot sites and scope defined [ ] Test data strategy approved [ ] Staff training owners assigned [ ] Acceptance criteria documented [ ] Cutover and rollback procedures documented [ ] Post-launch review cadence established This checklist is evaluation guidance, not certification, legal advice, or a representation that every listed integration/control is enabled in every deployment.