# Implementation Blueprint

This page shows what it takes to bring each part of Relyance online: the order to do it in, who to involve, how much effort each piece is and how long it usually takes.

:::info
Most of a Relyance rollout is not technical. Connecting a system is usually a read-only credential and a few clicks. The time goes into finding the right owner for each system and getting their approval.
:::

## Rollout plan

Source code and cloud come first, because they produce the map everything else hangs off. Data Subject Requests come last, since the workflows are easier to design once you can see where the data actually lives.

<div class="bp-roadmap">
<div class="bp-phase"><div class="bp-phase-k"><span class="bp-step">1</span>Foundation</div><ul class="bp-items">
<li class="bp-item"><a class="bp-link" href="#business-atlas">Business Atlas</a><span class="bp-when"><span class="bp-pill low">Low</span>1 hour</span></li>
<li class="bp-item"><a class="bp-link" href="#source-code">Source code</a><span class="bp-when"><span class="bp-pill low">Low</span>1–2 hours</span></li>
<li class="bp-item"><a class="bp-link" href="#cloud-infrastructure">Cloud infrastructure</a><span class="bp-when"><span class="bp-pill med">Low–Med</span>1 day–3 weeks</span></li>
</ul></div>
<div class="bp-phase"><div class="bp-phase-k"><span class="bp-step">2</span>Data</div><ul class="bp-items">
<li class="bp-item"><a class="bp-link" href="#data-stores-and-warehouses">Data stores and warehouses</a><span class="bp-when"><span class="bp-pill med">Med</span>1–2 weeks each</span></li>
</ul></div>
<div class="bp-phase"><div class="bp-phase-k"><span class="bp-step">3</span>AI and SaaS</div><ul class="bp-items">
<li class="bp-item"><a class="bp-link" href="#enterprise-ai">Enterprise AI</a><span class="bp-when"><span class="bp-pill low">Low</span>1–2 days</span></li>
<li class="bp-item"><a class="bp-link" href="#saas-apps">SaaS apps</a><span class="bp-when"><span class="bp-pill med">Med</span>2–4 weeks</span></li>
</ul></div>
<div class="bp-phase"><div class="bp-phase-k"><span class="bp-step">4</span>Requests</div><ul class="bp-items">
<li class="bp-item"><a class="bp-link" href="#data-subject-requests">Data Subject Requests</a><span class="bp-when"><span class="bp-pill high">High</span>4–8 weeks</span></li>
</ul></div>
</div>
<div class="bp-parallel"><span class="bp-pill med">Med</span><span class="bp-ptext"><a class="bp-link" href="#consent-management">Consent Management</a> does not depend on the others. Run it in parallel at any point, typically 2–4 weeks.</span></div>

Effort is the work on your side to get a connection live:

<ul class="bp-legend">
<li class="bp-l"><span class="bp-pill low">Low</span>One owner, one credential, done in a sitting.</li>
<li class="bp-l"><span class="bp-pill med">Medium</span>A few teams involved, or the same setup repeated across many accounts.</li>
<li class="bp-l"><span class="bp-pill high">High</span>Real configuration and decisions, not just a connection.</li>
</ul>

## Integrations

<div class="bp-cards">

<div class="bp-card">

### Business Atlas

<div class="bp-meta"><span class="bp-pill low">Low</span>1 hour</div>
<p class="bp-systems">Relyance</p>
<dl class="bp-rows"><dt class="bp-k">Involve</dt><dd class="bp-v">Privacy and legal</dd><dt class="bp-k">You do</dt><dd class="bp-v">Add your organizational hierarchy into Relyance.</dd><dt class="bp-k">Infra</dt><dd class="bp-v">None.</dd></dl>
</div>

<div class="bp-card">

### Source code

<div class="bp-meta"><span class="bp-pill low">Low</span>1–2 hours, then 10–20 minutes per repo</div>
<p class="bp-systems">GitHub · GitLab · Bitbucket</p>
<dl class="bp-rows"><dt class="bp-k">Involve</dt><dd class="bp-v">Engineering leadership, DevOps or platform team, repo admins</dd><dt class="bp-k">You do</dt><dd class="bp-v">Install the Relyance app at the org level and grant read access. Nothing to install on your side.</dd><dt class="bp-k">Infra</dt><dd class="bp-v">Read-only repo access. Self-hosted GitLab or Bitbucket needs a network path (IP allowlist or DirectConnect).</dd></dl>
</div>

<div class="bp-card">

### Cloud infrastructure

<div class="bp-meta"><span class="bp-pill med">Low–Medium</span>1–2 days for a few accounts, 2–3 weeks for hundreds</div>
<p class="bp-systems">AWS · GCP · Azure</p>
<dl class="bp-rows"><dt class="bp-k">Involve</dt><dd class="bp-v">Cloud or platform engineering, infrastructure security, IAM owners</dd><dt class="bp-k">You do</dt><dd class="bp-v">Create one read-only role per account. Easy for a handful; a rollout of its own for hundreds.</dd><dt class="bp-k">Infra</dt><dd class="bp-v">Agentless, via a cross-account role. Push it out with your account-provisioning tooling, not by hand.</dd></dl>
</div>

<div class="bp-card">

### Data stores and warehouses

<div class="bp-meta"><span class="bp-pill med">Medium</span>1–2 weeks per platform, mostly waiting on approvals</div>
<p class="bp-systems">Snowflake · Databricks · ClickHouse · S3 · BigQuery · RDS · PostgreSQL</p>
<dl class="bp-rows"><dt class="bp-k">Involve</dt><dd class="bp-v">Data engineering, DBAs, data platform owners, security</dd><dt class="bp-k">You do</dt><dd class="bp-v">Create a read-only service account per system and agree on when scans run.</dd><dt class="bp-k">Infra</dt><dd class="bp-v">Scans read real data on your compute, so run them off-peak and expect some query cost. Private databases need PrivateLink, VPC peering or DirectConnect.</dd></dl>
</div>

<div class="bp-card">

### Enterprise AI

<div class="bp-meta"><span class="bp-pill low">Low</span>1–2 days</div>
<p class="bp-systems">OpenAI · Anthropic · Bedrock · Vertex</p>
<dl class="bp-rows"><dt class="bp-k">Involve</dt><dd class="bp-v">AI/ML platform team, application engineering, AI governance and security</dd><dt class="bp-k">You do</dt><dd class="bp-v">Provide an admin-level API key per provider. Bedrock and Vertex are usually already covered by the cloud role.</dd><dt class="bp-k">Infra</dt><dd class="bp-v">Minimal. For runtime visibility, access to the logs or gateway your apps call models through.</dd></dl>
</div>

<div class="bp-card">

### SaaS apps

<div class="bp-meta"><span class="bp-pill med">Medium</span>About a day per app, 2–4 weeks end to end</div>
<p class="bp-systems">Salesforce · HubSpot · Greenhouse</p>
<dl class="bp-rows"><dt class="bp-k">Involve</dt><dd class="bp-v">Business system owners (sales, marketing, HR ops), IT admins</dd><dt class="bp-k">You do</dt><dd class="bp-v">Connect each app — 5–15 minutes once credentials are ready. The work is scheduling each app’s owner, not the connection.</dd><dt class="bp-k">Infra</dt><dd class="bp-v">Some apps need an admin account or a higher license tier for API access.</dd></dl>
</div>

<div class="bp-card">

### Data Subject Requests

<div class="bp-meta"><span class="bp-pill high">High</span>4–8 weeks, driven by your decisions</div>
<p class="bp-systems">DSR portal · intake forms · request workflows</p>
<dl class="bp-rows"><dt class="bp-k">Involve</dt><dd class="bp-v">Privacy and legal, DPO, customer support, web team, IT</dd><dt class="bp-k">You do</dt><dd class="bp-v">Decide how requesters are verified, which teams approve what, and how each system fulfills requests.</dd><dt class="bp-k">Infra</dt><dd class="bp-v">A branded portal needs a CNAME for your subdomain and a TLS certificate, or an embed on your site.</dd></dl>
</div>

<div class="bp-card">

### Consent Management

<div class="bp-meta"><span class="bp-pill med">Medium</span>2–4 weeks, longer for many sites or regions</div>
<p class="bp-systems">Website and CMS · tag manager · cookie banner · analytics and ad pixels · mobile SDKs</p>
<dl class="bp-rows"><dt class="bp-k">Involve</dt><dd class="bp-v">Privacy and legal, marketing and web, analytics or growth, front-end engineering</dd><dt class="bp-k">You do</dt><dd class="bp-v">Add the script — the easy part — then decide each tracker’s category and what stays blocked until consent.</dd><dt class="bp-k">Infra</dt><dd class="bp-v">A snippet on every page, and a tag manager that respects consent before firing. Configure each domain and region; add the script host to your CSP allowlist.</dd></dl>
</div>

</div>
