Guided onboarding¶
The guided setup at https://app.venturi.systems/domains/adoption/onboarding lets an authorized developer, Engineer, or Admin reach active use within ≤30 minutes through a connected evidence source. Venturi tenant, connector, federation, and external-ID setup artifacts are generated in-product. Customer-provided provider-account credentials are entered in-product. Credentials remain tenant-local and are validated for read-only access. No Venturi-human response or emailed setup value is required. See Docs authority & product state.
SaaS verification uses the quality
feed. For self-hosted
deployments, use the same /domains/quality/feed path on your own instance
host. File import is planned and unavailable
today; it is not part of this path.
Ordered setup path¶
Complete the steps in order. Each page names the required role, task, success evidence, and recovery action.
- Provision the tenant, IdP federation, and entitlement.
- Register provider credentials.
- Connect identity-resolution evidence.
- Map identity and cost dimensions.
- Deploy the connector.
- Verify the 1st
AttributionRecordin the quality feed. - Generate a chargeback-eligible export.
- Record Finance acceptance.
IdP federation in step 1 controls sign-in. The identity-resolution connector in step 3 supplies attribution evidence. They are separate controls.
Choose a cloud connector¶
- AWS: cross-account IAM role with external-ID scoping.
- Google Cloud: Workload Identity Federation with no exported keys.
- Azure: federated identity credential with no long-lived secret by default.
Every connector is read-only. Automated validation checks credentials, trust conditions, expected reads, and denied writes before activation.
Success evidence¶
The engineering active-use milestone is reached when at least 1 source is
accepted and its 1st AttributionRecord is visible in the quality feed with
coverage, unknown-state, and freshness evidence.
Persona-complete production onboarding additionally requires Product, Security, Engineering, and Finance paths to advance through real in-product actions, including Finance acceptance of a chargeback-eligible export. There is no admin or support override.
Recovery¶
Use the failed validation result to return to the responsible step. Rotate or revoke credentials in-product when trust is uncertain. Support is an optional escalation path, never a prerequisite.