Governance controls

Isolation, certificates, and a record of every decision.

BECCA Cloud is built for organizations that need to show, not just claim, how a workstation was used. Every control below is designed to be legible to an auditor as well as an administrator.

Dedicated organization tenancy

Each workstation and Edge Node is bound to one organization at a time. Capacity, BCC balance and audit history never cross organizational lines.

Certificate-based device trust

Nodes authenticate with a certificate scoped to your organization. Issuance, rotation and revocation are handled by provider-gated infrastructure.

Provider-disabled here

Execution and publishing gates

Workload execution and any public-facing publishing action require a named approver before they can proceed. Neither happens implicitly.

Approval required

Immutable audit log

Every session start, stop, approval decision and BCC draw-down is written to an append-only log your organization can review on demand.

Decision flow

What happens between a request and a running session.

Governance isn't a single checkbox — it's a sequence of gates a workload has to pass. This is the same chain shown on the workflow page, viewed from a controls perspective rather than a customer journey.

Identity check

Node certificate verified against the requesting organization before anything is accepted.

Policy match

Workload type and requested capacity checked against your package and any org-level policy.

Named approval

A designated approver reviews and clears the request — no workload auto-approves.

Metered execution

Session runs in an active state, drawing BCC for the duration of the work.

Audit write

Outcome, timing and BCC draw are appended to the immutable log.

Compliance posture

What's provider-gated today, in plain terms.

Certificate issuance

Certificates authenticate every node. Issuance, rotation and revocation run through provider-gated infrastructure, not this marketing site.

Provider-gated

Authentication

Sign-in to the client portal is handled on its own authenticated domain, separate from this public site.

Provider-gated

Live BCC metering

Real-time balance and draw-down figures are only available once your organization is provisioned and metering is enabled by the provider.

Provider-gated