Skip to content

// installation

Go-live

Applies to

Product: Cloud · Audience: Administrator · IT · Data protection

Checklist for taking a basebox Cloud environment into production. basebox operates the infrastructure – your preparation concerns the application, the organisation and the connection to your systems. Work through the items in this order; each links to the page with the details.

1. Contract and responsibility

  • Contract signed; environment provisioned at <your-organisation>.basebox.ai
  • Data processing agreement (DPA) concluded with basebox – in the Cloud, basebox processes data on your behalf; see GDPR
  • Data protection officer involved; Security & Compliance → Cloud reviewed
  • Support channels and response times known; internal contact person named
  • Responsibilities understood: basebox operates, you administer – Responsibilities

2. Access and identity

  • First administrator signed in, password changed
  • Second administrator created – never keep only one
  • Identity model decided: local accounts, OIDC / single sign-on (recommended in the Cloud) or LDAP with private connectivity
  • With SSO: client registered with your provider, basebox has registered the identity provider, test login successful
  • Groups created that you need for sharing

3. Organisation and policies

  • Name and logo under Organisation
  • System prompt with organisation-wide rules (language, style, blocked topics)
  • Settings: welcome message, language, limits, mail configuration tested
  • Policies: audit log retention and detail level agreed with data protection; notice in the chat understood
  • Message of the day prepared for the launch (optional)

4. Models and apps

  • Default model chosen in Model selection; context size checked under "About"
  • Shipped apps reviewed; unneeded ones removed – Managing apps
  • First custom apps created, knowledge bases checked (only content everyone shared with may see)
  • Reasoning default and thinking effort per app set deliberately – Default models
  • App sharing with groups rather than individuals; publishing only for general apps

5. Connectors and external services

  • Decision on web search: off, or in a dedicated app for a defined group – following the Introduction to web search security
  • Connectors to business systems: access model decided, base URLs configured, connection tested, enabled per app – Configuring connectors
  • Firewall rules from the Cloud's egress addresses to your target systems set – Network connectivity
  • Users know how to generate and enter personal tokens
  • Write tools enabled only where intended

6. API

  • Decision whether integrations use the API; API keys issued per integration
  • Developers know base URL and X-Realm – Quickstart

7. Preparing users

8. Operations after launch

  • Weekly: check the Dashboard for consumption and limits
  • Monthly: review users, roles, sharing and connectors; departed people removed
  • Regularly: export the audit log if evidence is needed longer than the retention period
  • Keep an eye on the changelog: basebox updates the environment; changes are in the Changelog
  • Procedure for security incidents known: report to datenschutz@basebox.ai – see Safety Notice

What you do not have to do

No installation, no updates, no platform backups, no infrastructure monitoring, no GPU planning – that is basebox's part. Your task is the application, and this list covers it.

Need help with the go-live? Contact support