Help Center

Review workspace security controls

Check access, provider policy, evidence and retention before a team moves from evaluation to production.

Typical time: 30–60 minutes For: Customer administrators, security, privacy and procurement teams Before you start: Workspace administrator, security owner and intended data classes
Product guide · Updated 20 July 2026

Use the system as one operating record

Public security pages describe the FrescoAds control approach; deployment-specific evidence, providers, regions and contractual commitments are confirmed during enterprise review. FrescoAds does not claim a certification publicly unless its scope has been independently verified.

  • Workspace and role boundaries
  • Provider and data-routing policy
  • Review and release evidence
  • Deployment-specific enterprise review
01

Define the production data boundary

List the data expected in accounts, briefs, prompts, reference files, generated outputs, comments and connected applications. Identify sensitive or regulated data that should remain outside the platform unless a written agreement expressly permits it.

The customer remains responsible for the lawfulness of submitted content and instructions. Use the Privacy Policy and DPA to distinguish FrescoAds controller activities from customer-directed processing.

Check before continuing

  • Intended data classes documented
  • Restricted data excluded
  • Customer responsibility is understood
  • Privacy and DPA contacts identified
02

Review identity and workspace access

Confirm administrator coverage, workspace scope, role assignments, organization domains and agency participation. Remove dormant or unnecessary users before production content is introduced.

Organization-managed login is required. Enterprise SSO routing and enforcement are deployment-specific and should be tested against the contracted identity path.

Check before continuing

  • Role-based access reviewed
  • External access scoped
  • Administrator recovery path known
  • SSO requirements tested where applicable
03

Review providers and connected services

Map each production task to the providers enabled for the workspace and the source-data classes permitted for that route. Verify the actual deployment information rather than assuming every provider shown publicly is active.

Review connected identity, storage, advertising or other applications separately. Customer-authorized connections can introduce their own terms and data flows.

Check before continuing

  • Active provider set approved
  • Task and data rules documented
  • Fallback routes follow policy
  • Connected applications have owners
04

Review campaign governance

Confirm that important configuration changes, current versions, comments, approvals and release actions create usable operational evidence. Decide which review stages block export and who can change those rules.

The platform record supports accountability, but the customer must define an appropriate review policy for its content and markets.

Check before continuing

  • Required review stages approved
  • Policy-change ownership is clear
  • Release blockers are tested
  • Decision evidence can be retrieved
05

Align retention, deletion and incident contacts

Compare workspace expectations with the Privacy Policy, DPA and customer agreement. Identify who can request return or deletion, what protected backup exceptions apply and where incident notices should be delivered.

Do not infer a universal retention period from this guide; contracted deployment terms and applicable law control.

Check before continuing

  • Retention owner named
  • Termination and deletion path understood
  • Incident contacts confirmed
  • Backup exceptions reviewed
06

Request and evaluate deployment evidence

Ask FrescoAds for the architecture, active provider, transfer and control information applicable to the intended deployment. Evaluate only evidence that matches the service and region being contracted.

Unsupported badges or broad certification claims should not be used as substitutes for deployment-specific review.

Check before continuing

  • Applicable evidence requested
  • Provider and region scope match
  • Open risks have owners
  • Commercial and legal documents are aligned
07

Approve the production boundary

Record the approved users, data classes, provider routes, connected applications and review requirements. Resolve material exceptions before allowing the workspace to process real campaign content.

Repeat the review after material changes to providers, identity, integrations or intended data.

Check before continuing

  • Production boundary documented
  • Exceptions are resolved or accepted
  • Review date and owner recorded
  • Change-triggered review is planned

The intended deployment has an owned and reviewable control boundary.

People, data, providers, decisions and lifecycle expectations are aligned with the customer agreement, and no public marketing claim is being used as a substitute for deployment evidence.

  • Access and provider policy approved
  • Retention and incident paths confirmed
  • Deployment evidence and open risks recorded

Clarify the operating boundary

Only completed, independently verified certifications will be named publicly with their scope. The current public site describes controls without an unsupported badge.

Follow the campaign workflow

Workspace setupCreate a workspaceSet up regions, brands, markets and the people responsible for each decision.Launch readinessPrepare launch exportsConfirm format, language, offer and approval readiness before work leaves the platform.Campaign planningBuild a campaign briefTurn the objective, audience, offer, product truth and market requirements into one production record.