Offboarding and Exit Strategy
This document defines the technical protocol and strategic pathways for anDREa's exit strategy, ensuring that Tenant organizations can quickly, cleanly, and legally reclaim full control of their data and infrastructure assets. This strategy supports compliance mandates for vendor offboarding and continuity under *ISO 27001:2023 (A.05.22 - Control of Supplier Services) and NIS 2 (Business Continuity & Supply Chain Integrity).
1. Architectural Foundations of Data Ownership
The myDRE platform is engineered around the principle of strict tenant data sovereignty. This architectural choice radically simplifies de-provisioning and exit procedures.
- Subscription Enclosure: By design, all research datasets, configuration states, fileshares, and virtual machines (VMs) are processed and stored exclusively inside Microsoft Azure subscriptions owned and billed directly to the Tenant.
- Control Delegation: To operate the myDRE platform, the Tenant temporarily associates their cloud subscriptions with the centralized anDREa Entra ID (identity plane) via an automated onboarding session.
- Legal and Financial Reality: The Tenant remains the absolute legal owner of these cloud environments throughout the entire service lifecycle. All raw Microsoft Azure consumption fees are billed directly to the Tenant by their chosen cloud provider, completely bypassing anDREa financial planes.
2. De-provisioning & Exit Pathways
If a Tenant chooses to terminate their relationship with anDREa or reclaim standalone management of their cloud subscriptions, they can execute one of three structured exit strategies.
Pre-requisite Control (All Options): Before breaking the identity plane connection, Local Research Support or Tenant Security Officers must extract a complete access entitlement matrix from admin.mydre.org. This report details exactly which researchers held active permissions and technical roles across every live resource, preserving a forensic compliance audit trail.
Option 1: Accelerated Re-association ("Quick and Dirty")
- Operational Execution: A coordinated one-hour technical synchronization session is scheduled between anDREa engineers and Tenant infrastructure administrators.
- Action: The Tenant's Azure subscriptions are instantly disassociated from the anDREa Entra ID and re-anchored back to the Tenant's native corporate identity directory.
- Post-State: The underlying myDRE software hooks and orchestration packages remain dormant within the subscription, but all external management lines are severed.
Option 2: Full System Purge ("Clean Exit")
- Operational Execution: anDREa engineers systematically strip out platform components before re-associating the directory. This requires approximately half a business day per subscription.
- Action: All myDRE orchestration templates, centralized monitoring connectors, automation APIs, and platform configuration blocks are completely uninstalled from the environment.
- Action: A one-hour synchronization session is executed to move the completely cleaned subscriptions back under the Tenant's native corporate Entra ID.
Option 3: Autonomous Provider Reclamation (Zero anDREa Interaction)
- Operational Execution: The Tenant can execute a complete exit autonomously without requesting cooperation or authorization from anDREa.
- Action: The Tenant issues a direct corporate instruction to their primary Microsoft Azure Provider / Licensing reseller to programmatically migrate the target subscriptions back under the exclusive jurisdiction of the Tenant's master billing agreement and root directory.
- System Safeguard: This path leverages native Microsoft enterprise security rules to override anDREa's control plane access seamlessly.
3. Post-Exit Operational State
The moment any of the three exit options are completed, the structural results are immediate and absolute:
- Total Tenant Control: The Tenant assumes instant, unmitigated administrative ownership of all underlying storage accounts, database files, and Virtual Machines.
- Sovereign Policy Application: The Tenant can immediately apply their internal corporate security frameworks, Role-Based Access Controls (RBAC), patch parameters, and identity management policies to the recovered infrastructure.
- Zero-Access Posture: Because the link to the centralized anDREa Entra ID is severed, all external user access pathways are completely closed. No researcher, external collaborator, or anDREa system process can interact with any VM or access any storage account until the Tenant's internal administrators manually provision brand-new identity credentials.