Copyright © 2022-2026 basebox GmbH, all rights reserved.
Licensed to be used in conjunction with basebox, only.
Licensed to be used in conjunction with basebox, only.
// installation
Go-live
Applies to
Product: Cloud · Audience: Administrator · IT · Data protection
Checklist for taking a basebox Cloud environment into production. basebox operates the infrastructure – your preparation concerns the application, the organisation and the connection to your systems. Work through the items in this order; each links to the page with the details.
1. Contract and responsibility
- Contract signed; environment provisioned at
<your-organisation>.basebox.ai - Data processing agreement (DPA) concluded with basebox – in the Cloud, basebox processes data on your behalf; see GDPR
- Data protection officer involved; Security & Compliance → Cloud reviewed
- Support channels and response times known; internal contact person named
- Responsibilities understood: basebox operates, you administer – Responsibilities
2. Access and identity
- First administrator signed in, password changed
- Second administrator created – never keep only one
- Identity model decided: local accounts, OIDC / single sign-on (recommended in the Cloud) or LDAP with private connectivity
- With SSO: client registered with your provider, basebox has registered the identity provider, test login successful
- Groups created that you need for sharing
3. Organisation and policies
- Name and logo under Organisation
- System prompt with organisation-wide rules (language, style, blocked topics)
- Settings: welcome message, language, limits, mail configuration tested
- Policies: audit log retention and detail level agreed with data protection; notice in the chat understood
- Message of the day prepared for the launch (optional)
4. Models and apps
- Default model chosen in Model selection; context size checked under "About"
- Shipped apps reviewed; unneeded ones removed – Managing apps
- First custom apps created, knowledge bases checked (only content everyone shared with may see)
- Reasoning default and thinking effort per app set deliberately – Default models
- App sharing with groups rather than individuals; publishing only for general apps
5. Connectors and external services
- Decision on web search: off, or in a dedicated app for a defined group – following the Introduction to web search security
- Connectors to business systems: access model decided, base URLs configured, connection tested, enabled per app – Configuring connectors
- Firewall rules from the Cloud's egress addresses to your target systems set – Network connectivity
- Users know how to generate and enter personal tokens
- Write tools enabled only where intended
6. API
- Decision whether integrations use the API; API keys issued per integration
- Developers know base URL and
X-Realm– Quickstart
7. Preparing users
- Invitations sent (valid 14 days); enough licence seats
- Short internal usage rule distributed: no confidential details in web search; verify results; use personalisation
- Entry pages known: Signing in · Understanding the interface · Start your first conversation
- AI literacy training planned – an operator obligation under the EU AI Act; see Compliance
8. Operations after launch
- Weekly: check the Dashboard for consumption and limits
- Monthly: review users, roles, sharing and connectors; departed people removed
- Regularly: export the audit log if evidence is needed longer than the retention period
- Keep an eye on the changelog: basebox updates the environment; changes are in the Changelog
- Procedure for security incidents known: report to datenschutz@basebox.ai – see Safety Notice
What you do not have to do
No installation, no updates, no platform backups, no infrastructure monitoring, no GPU planning – that is basebox's part. Your task is the application, and this list covers it.
Need help with the go-live? Contact support