Business-rebuild work can involve commercially sensitive systems, databases, reports, workflows and operational information.
That requires clear boundaries before technical work begins.
Core principles
- Written management authorisation before access.
- A defined scope stating which systems and data are in scope.
- Least-privilege access wherever practical.
- Credentials handled securely and not embedded unnecessarily in project files.
- Encryption and secure remote access appropriate to the environment.
- Clear retention and deletion rules for copied data, diagnostics and logs.
- Backups before significant change.
- Testing and rollback plans before production transition.
- Confidentiality and NDA arrangements where required.
System observation is not employee surveillance
In some legacy environments it may be useful to use temporary diagnostic logging, system-event capture or other technical observation to understand what an application actually does.
That must be authorised, scoped, proportionate and technically justified.
It is not intended to secretly monitor, time or judge employees.
If a proposed method creates inappropriate privacy or employment concerns, another discovery method should be used.
International work
Remote international work can add privacy, data-transfer, cybersecurity, contractual and regulatory considerations. Those issues should be assessed for the actual customer and jurisdiction rather than hidden behind generic website promises.
Discuss your environment →