Customer onboarding

A controlled path from approval to operational protection.

MindShield onboarding separates identity verification, organization provisioning, installer access and workload activation so that each stage can be reviewed and audited.

Operational sequence

What your team should expect.

1

Eligibility review

Confirm workload, authority, plan and deployment boundaries.

2

Email verification

Verify the primary administrator through an expiring link.

3

Organization provisioning

Create the country, currency, timezone and tenant scope.

4

Administrator setup

Establish the first administrator with least-privilege access.

5

Installer authorization

Provide the approved package, version and integrity details.

6

Device activation

Register the device to the correct organization and license.

7

SQL discovery

Review discovered SQL Server instances and required permissions.

8

Protection validation

Create a policy, run a backup and review verification evidence.

Security controls

Controls built around the onboarding boundary.

Verified identity

Email verification and expiring onboarding tokens.

Tenant scope

Organization-scoped provisioning with no cross-tenant activation.

Abuse prevention

Rate limiting, bot filtering and eligibility review.

Audit evidence

Request, provisioning and activation events designed for audit logging.

No exposed keys

Activation keys are never embedded in static HTML or JavaScript.

Least privilege

Agent and SQL permissions are reviewed against the supported workflow.

Controlled release

Installer access is tied to an approved release channel.

Safe transition

Existing backups remain active until acceptance is complete.

Communication sequence

Lifecycle messages without exposing secrets.

Operational emails should guide the user to authenticated actions rather than placing credentials or sensitive configuration in the message body.