The provider runs the application and underlying platform, while the customer controls tenant settings, user access, data sharing, connected applications, and aspects of retention and monitoring. Exact responsibilities depend on the service and contract.
The term covers both provider and customer perspectives; this definition emphasizes customer use. With little access to underlying systems, customers depend on provider assurance, supported settings, audit data, incident coordination, portability, and exit arrangements.
Key points
Service governanceApprove services and use cases, classify permitted data, assess provider and subprocessor responsibilities, assign an owner, and maintain renewal and exit decisions.
Identity and configurationFederate authentication where appropriate, enforce strong administration and least privilege, govern sharing and guest access, review defaults, and protect recovery and emergency accounts.
Data and integrationsControl application consent, API tokens, automation, imports, exports, retention, deletion, and backups; collect useful events without assuming the provider records every relevant action.
Important limitationA secure provider does not make a tenant’s permissions, sharing, integrations, endpoints, or data handling safe, while careful tenant configuration cannot remove provider compromise or outage risk. SaaS APIs, logs, encryption choices, recovery options, and administrative controls may also be limited by the service or subscription tier.