Active initiative · 04

Extending customer-controlled analysis

More private deployment, isolation, retention, regional, and worker controls for sensitive source environments.

In active developmentEvidence-led product capability
Software components being inspected inside a controlled analysis boundary
DeploymentCustomer-controlled options
RetentionConfigurable to zero
ExecutionIsolated workers

Capability overview

Built around a verifiable operating model.

Some engineering organizations require source analysis to operate inside stricter network, regional, and retention boundaries. We are extending CutoverGrid deployment options so customers can choose where analysis workers run, how they reach source systems, which outbound destinations are permitted, how long artifacts and evidence are retained, and which controls are managed by customer security teams.

The design separates the control plane from analysis execution. Short-lived workers receive scoped jobs and credentials, perform approved deterministic checks, return the permitted evidence, and are destroyed. Package lifecycle scripts and unapproved network activity remain disabled by default. Private connectivity and customer-managed deployment patterns add control without breaking the evidence model used by migration planning.

How it works

From source context to operational control.

01

Configure

Choose region, network path, worker placement, retention, and approved integrations.

02

Authorize

Issue short-lived repository access for a specific analysis job.

03

Execute

Run deterministic checks inside the selected isolated boundary.

04

Dispose

Return allowed evidence, remove temporary artifacts, and record the control history.

Evidence produced

Every decision remains inspectable.

The capability produces structured evidence that can be reviewed by engineers and reused by downstream planning and verification.

Policy snapshot

Deployment, region, retention, network, and execution settings applied to the job.

Worker identity

Ephemeral worker, tenant, job, repository scope, and lifecycle timestamps.

Access events

Credential issue, source read, approved outbound access, and revocation.

Deletion proof

Artifact retention decision, disposal state, and customer-requested deletion history.

Operational impact

Why this capability matters.

Customer-controlled analysis allows security-sensitive organizations to adopt repository-scale migration intelligence without weakening their source-code controls. Platform and security teams can review the technical boundary as part of the product rather than relying on an informal promise.

See it in a migration assessment

Migration control in practice

Connect the evidence to an executable plan.

Start with the repositories, define the target transition, and see the technical and operational work required.