An operating boundary includes data, inference, identities, keys, logs, backups and the people who can access them. It also includes the dependencies that the organisation relies on when the system changes or fails.
Follow a request all the way through.
Where does the source material come from? Where is context prepared? Which model processes it? What is recorded? Who can inspect or administer each part? These questions connect an architectural drawing to an operating reality.
An Australian deployment needs its actual arrangements described. Provider selection, support access and contractual responsibilities are part of that description.
Control should be something you can explain, inspect and exercise.
Design for the day after delivery.
The organisation needs a workable way to monitor, recover, update and eventually move the system. Clear responsibilities and practical documentation help make that possible.
The Australian Government’s Hosting Certification Framework addresses ownership, control, operations and supply chains within its government hosting scope. It is a useful source for those considerations, not a certification claim about Form From.
Our reference operating model makes the areas to specify visible. The actual boundary belongs in the architecture and agreement for each programme.