Docs
relyance.ai ↗
Browse docs

Implementation Blueprint

Updated June 17, 2024View as Markdown ↗

This page shows what it takes to bring each part of Relyance online: the order to do it in, who to involve, how much effort each piece is and how long it usually takes.

Note

Most of a Relyance rollout is not technical. Connecting a system is usually a read-only credential and a few clicks. The time goes into finding the right owner for each system and getting their approval.

Rollout plan

Source code and cloud come first, because they produce the map everything else hangs off. Data Subject Requests come last, since the workflows are easier to design once you can see where the data actually lives.

1Foundation
2Data
3AI and SaaS
4Requests
MedConsent Management does not depend on the others. Run it in parallel at any point, typically 2–4 weeks.

Effort is the work on your side to get a connection live:

  • LowOne owner, one credential, done in a sitting.
  • MediumA few teams involved, or the same setup repeated across many accounts.
  • HighReal configuration and decisions, not just a connection.

Integrations

Business Atlas

Low1 hour

Relyance

Involve
Privacy and legal
You do
Add your organizational hierarchy into Relyance.
Infra
None.

Source code

Low1–2 hours, then 10–20 minutes per repo

GitHub · GitLab · Bitbucket

Involve
Engineering leadership, DevOps or platform team, repo admins
You do
Install the Relyance app at the org level and grant read access. Nothing to install on your side.
Infra
Read-only repo access. Self-hosted GitLab or Bitbucket needs a network path (IP allowlist or DirectConnect).

Cloud infrastructure

Low–Medium1–2 days for a few accounts, 2–3 weeks for hundreds

AWS · GCP · Azure

Involve
Cloud or platform engineering, infrastructure security, IAM owners
You do
Create one read-only role per account. Easy for a handful; a rollout of its own for hundreds.
Infra
Agentless, via a cross-account role. Push it out with your account-provisioning tooling, not by hand.

Data stores and warehouses

Medium1–2 weeks per platform, mostly waiting on approvals

Snowflake · Databricks · ClickHouse · S3 · BigQuery · RDS · PostgreSQL

Involve
Data engineering, DBAs, data platform owners, security
You do
Create a read-only service account per system and agree on when scans run.
Infra
Scans read real data on your compute, so run them off-peak and expect some query cost. Private databases need PrivateLink, VPC peering or DirectConnect.

Enterprise AI

Low1–2 days

OpenAI · Anthropic · Bedrock · Vertex

Involve
AI/ML platform team, application engineering, AI governance and security
You do
Provide an admin-level API key per provider. Bedrock and Vertex are usually already covered by the cloud role.
Infra
Minimal. For runtime visibility, access to the logs or gateway your apps call models through.

SaaS apps

MediumAbout a day per app, 2–4 weeks end to end

Salesforce · HubSpot · Greenhouse

Involve
Business system owners (sales, marketing, HR ops), IT admins
You do
Connect each app — 5–15 minutes once credentials are ready. The work is scheduling each app’s owner, not the connection.
Infra
Some apps need an admin account or a higher license tier for API access.

Data Subject Requests

High4–8 weeks, driven by your decisions

DSR portal · intake forms · request workflows

Involve
Privacy and legal, DPO, customer support, web team, IT
You do
Decide how requesters are verified, which teams approve what, and how each system fulfills requests.
Infra
A branded portal needs a CNAME for your subdomain and a TLS certificate, or an embed on your site.
Medium2–4 weeks, longer for many sites or regions

Website and CMS · tag manager · cookie banner · analytics and ad pixels · mobile SDKs

Involve
Privacy and legal, marketing and web, analytics or growth, front-end engineering
You do
Add the script — the easy part — then decide each tracker’s category and what stays blocked until consent.
Infra
A snippet on every page, and a tag manager that respects consent before firing. Configure each domain and region; add the script host to your CSP allowlist.