Skip to content

Shared responsibility

The managed application reduces infrastructure work, but it does not transfer ownership of your Azure subscription, identities, network, or data to iVedha.

Responsibility swimlane showing customer ownership of subscription, network and DNS, identity, and data governance, alongside iVedha Opsflw ownership of provisioning, supported configuration, health monitoring, upgrades, and operations.

The customer owns Azure and data decisions. iVedha and Opsflw manage the supported platform lifecycle without owning the customer's infrastructure.

Responsibility overview

Area Customer iVedha
Azure subscription, billing, policy, and quota Own and approve Identify deployment requirements
Marketplace purchase and managed application Select, create, and delete Package and support the application
Managed infrastructure Avoid unsupported changes Provision and operate supported components
Network routes, peering, and client DNS Configure customer-side connectivity Provide authoritative deployment endpoints
Private Endpoint Create in the client network Expose the deployment Private Link Service
TLS Approve names and trust chain Apply supported certificate material
Elasticsearch data and retention Classify, ingest, retain, and delete data Operate the managed platform
Elasticsearch users and roles Assign least-privilege access Provide supported access mechanisms
Snapshots and recovery objectives Define and test requirements Provide verified platform workflows
Monitoring and support evidence Monitor workload outcomes and report symptoms Operate the managed-resource monitoring agent, receive its telemetry in the iVedha monitoring cluster, and investigate platform health

Microsoft operates Azure and enforces the Azure Managed Application and Marketplace contracts. Elastic defines Elasticsearch and Kibana product behavior, APIs, security features, and version compatibility.

The monitoring agent in the managed resource group forwards operational platform telemetry to the iVedha monitoring cluster for health monitoring and incident response. This monitoring flow does not transfer ownership of the customer's Azure resources, Elasticsearch indices, or application data to iVedha.

Customer safety rules

  • Do not edit, move, or delete resources in the managed resource group.
  • Do not reconstruct internal resource names from naming conventions.
  • Do not share passwords, private keys, access tokens, or unredacted diagnostics in tickets.
  • Obtain endpoint names and resource IDs from deployment details.
  • Test backups, access changes, and client configuration in a non-production environment when one is available.

Deleting the Azure managed application also deletes its managed resource group. Review delete the application before decommissioning.