TRUST / FOXBYTE SYSTEMS
Trust starts with clear responsibilities.
Before approving technology work, understand what is included, who can act and how the result will be checked. This page sets out the questions that make an engagement reviewable.
Make the promise specific
| Area | What to establish before work |
|---|---|
| Scope | The systems, users, sites and activities included, plus explicit exclusions. |
| Authority | Who can approve work, provide access and authorise a change. |
| Acceptance | The checks and records that will demonstrate the agreed result. |
| Commercial terms | Fees, dependencies, payment stages and the change process. |
| Support | Channels, hours, response commitments and any separately contracted escalation. |
| Handover | Access ownership, configuration records, training and remaining responsibilities. |
Keep access proportionate
Provide access only after the work and authorised people are identified. Prefer named accounts and the permissions needed for the task. Agree how temporary access will be reviewed or removed when the work ends.
- Do not place passwords, recovery keys or payment secrets in an initial enquiry.
- Identify the customer decision maker for sensitive changes.
- Document who owns administrator accounts and any service subscriptions.
- Agree the appropriate channel for necessary access or confidential material.
- Review access at handover and when a person or supplier changes.
Match the evidence to the claim
| Evidence type | What it can establish | What it cannot establish alone |
|---|---|---|
| A process explanation | The proposed logic and responsibilities. | That it has run successfully in a customer environment. |
| A synthetic demonstration | How selected example inputs and branches behave. | Real customer savings, coverage or integration success. |
| Implementation checks | What was inspected on an identified configuration. | Every possible operating condition or future result. |
| Owner acceptance | The customer’s review of the agreed scope at a point in time. | A perpetual guarantee or an unrelated certification. |
Security coverage needs operational ownership
Endpoint software, account controls, backup and network settings are parts of a wider security programme. Ask who maintains them, who reviews failures and who can authorise action. Automated detection does not by itself establish a staffed response service.
Specialist activities such as penetration testing, digital forensics, managed detection and response, or emergency incident response require confirmed capability and a separate written scope where offered. Do not infer them from a general cybersecurity page.
Read the cybersecurity scopePrivacy and service terms
Review the published policies and the terms applicable to your engagement. Site-level policy wording and project-specific handling arrangements answer different questions. If the work involves sensitive data, agree the necessary handling, access and retention terms before transferring it.
Questions worth asking
Can I treat this page as a certification?
No. It explains engagement questions and responsibilities. Specific certifications or contractual commitments require their own verified evidence.
Where are customer results and references?
Only evidence that is authorised and accurately labelled should be presented. The demonstration library currently explains synthetic processes; it does not turn those examples into customer case studies.
Does an online enquiry authorise access or work?
No. Access, scope and approval must be agreed through the appropriate process.
How are changes beyond scope handled?
Identify the requested change, its implications and the person authorised to approve it before treating it as part of delivery.
Ask for the scope and evidence you need.
Tell us the decision you are evaluating and the assurance questions that matter to your organisation.
Foxbyte Insights
Prepare for the decision.
Cybersecurity
Questions to ask a managed security provider before signing
Compare managed security providers by the work they are accountable for. A long product list is less useful than a precise description of coverage, decisions, response and reporting.
Foxbyte InsightsPublished Updated
Read the guide: Questions to ask a managed security provider before signingComputer Support
Before computer repair: make a data and access handover plan
Before repair, agree what data must be preserved and what access the assessor actually needs. A repair instruction should not silently authorise a reset, reinstall or unrestricted examination of personal files.
Foxbyte InsightsPublished Updated
Read the guide: Before computer repair: make a data and access handover planAI & Automation
What business data should you put into an AI tool?
Decide whether a tool is authorised for the information before entering business data. A useful AI response does not establish permission to share the underlying records.
Foxbyte InsightsPublished Updated
Read the guide: What business data should you put into an AI tool?