MCMMCM DocsEngineering (Internal)
User StoriesMCM-57 — Legal & Compliance Readiness for Customer Deployment
v1.2 is unreleased — see v1.1 for the current stable release.

MCM-57 — Legal & Compliance Readiness for Customer Deployment

Overview of the legal and compliance deliverables that must be in place before MCM is deployed into a customer's environment.

MCM-57 — Legal & Compliance Readiness for Customer Deployment

MCM is a multi-cloud governance, security, and cost management platform that requires cross-account access into a customer's cloud environment, processes their discovery, security, and cost data, and increasingly uses an AI assistant to draft policies and suggest actions. Deploying it into a customer's environment carries legal and compliance obligations well beyond typical SaaS onboarding — data processing terms, access-scope commitments, licensing, open-source obligations, security certifications, incident response commitments, liability, audit rights, and export control all need to be resolved before the first production deployment.

Each user story below is a self-contained deliverable with its own acceptance criteria, a short technical note on how it ties back to the platform, and — where relevant — a diagram of the review or approval flow. This page holds only what's shared across all of them.


Personas

PersonaRolePrimary concern
Legal CounselDrafts and negotiates contracts, DPAs, and compliance terms for MCMEnforceable, risk-appropriate legal terms in place before any customer deployment
Compliance & Security LeadOwns certification, vulnerability management, and audit/pen-test readinessPassing customer security reviews and keeping certifications and processes current
Enterprise Sales / Deal DeskRuns the commercial deal and contracting process with prospective customersClosing deals without legal terms blocking or delaying signature
Engineering LeadOwns the dependency inventory, SBOM output, and export classification inputsProducing accurate, current compliance artifacts on demand

System Context


User Stories

StorySummary
MCM-58 — Data Processing Agreement & Controller/Processor ClarityA standard DPA and a documented controller/processor determination per deployment model.
MCM-59 — Cross-Account Access & Least-Privilege CommitmentsDocumented, contractually-committed least-privilege scopes for every cross-account role MCM requests.
MCM-60 — AI Assistant Data Handling & Human-in-the-Loop GovernanceNo-training terms, disclosure, and a mandatory human approval step for every AI-suggested action.
MCM-61 — Licensing Model & Contract TemplatesFinalized on-prem/hosted licensing models with approved EULA/MSA templates.
MCM-62 — Open Source License Compliance & SBOM DeliverableA current SBOM and a clean open-source license audit for every release.
MCM-63 — Security Compliance CertificationsSOC 2 Type II, ISO 27001/27017/27018, and PCI DSS scoping where applicable.
MCM-64 — Vulnerability Management & Incident/Breach Notification SLADocumented severity SLAs and a contractual breach-notification window.
MCM-65 — Liability Caps, Indemnification & InsuranceBounded, insured financial exposure, including security-tool-specific liability language.
MCM-66 — Customer Audit & Penetration Testing RightsControlled audit and pen-test rights a customer's security team can exercise before deployment.
MCM-67 — Export Control Classification ReviewECCN (or equivalent) classification covering cryptographic and AI components, reviewed per release.

Cross-Cutting Non-Functional Requirements

IDRequirement
NFR-01Every deliverable in this module must be complete for a given deployment model before the first customer's cross-account access is granted in production under that model.
NFR-02Customer-facing compliance artifacts (DPA, SBOM, certification reports, insurance certificates) are kept current and reissued at every major release or annually, whichever comes first.
NFR-03Any new module or materially new capability (e.g., a new AI-driven action, new cryptographic functionality) triggers a review of every story in this module for continued accuracy — none of these are one-time determinations.

Out of Scope

  • Negotiating terms for any single specific customer deal — this module defines the standard templates and processes; per-deal negotiation is handled by Legal Counsel and Deal Desk against that baseline.
  • Country-specific data residency requirements beyond a GDPR/CCPA-equivalent baseline — handled case-by-case if a specific customer requires it.
  • Physical security or facility compliance for MCM's own corporate offices — this module covers the platform and its deployment into customer environments only.

On this page