Enterprise onboarding
Contract to first production deployment, in six phases. Every phase has an owner, an artefact that proves it’s done, and a hard gate before the next phase starts.
Phase overview
| # | Phase | Duration | Owner | Exit artefact |
|---|---|---|---|---|
| 01 | Kickoff & scope confirmation | 3 days | Nebbos deployment lead | Signed statement of work |
| 02 | Identity & tenancy provisioning | 5 days | Ops + your IT | WorkOS SSO live; test operator identities issued |
| 03 | Cradle provisioning | 7 days | Ops + your named operators | Cradles received, provisioned, first attested read landed in the chain |
| 04 | Data ingestion & Pearl training | 10 days | Onboarding & ed team + your ops team | Pearls answering scoped questions with citation trail |
| 05 | Approval-graph configuration | 5 days | Onboarding & ed team + your compliance team | Approval graphs live; first attested write end-to-end |
| 06 | Production sign-off | 3 days | Your security officer + Nebbos deployment lead | Signed production-readiness attestation |
Total: 33 business days end-to-end. Faster is possible on a smaller deployment; slower is possible on a highly regulated one.
Phase 01 · Kickoff & scope confirmation
Kickoff call (60 min)
Nebbos deployment lead, your executive sponsor, your ops lead, your security lead. Confirm scope, identify blockers, agree on the artefacts each side will produce.
Written scope confirmation
Nebbos issues a written statement naming the departments, the operator identities, the Cradle count, and the exit-criterion for production sign-off. You sign it.
Slack / Teams shared channel opens
A dedicated shared channel between your team and the Nebbos deployment team. Every artefact in the next five phases lands in this channel; nothing lives in email.
Phase 02 · Identity & tenancy provisioning
WorkOS connection
Your IT team configures the SSO connection to your IdP (Okta, Azure AD, Google Workspace, or SAML 2.0). Nebbos hands you a step-by-step for each; the whole flow takes 30–60 min once the IdP admin is available.
Group / department mapping
You define which of your IdP groups map to which Nebbos departments and which operator tier they authorize. This is where the platform’s tier gates get anchored to your existing identity plane.
Test operator identities
Two identities per tier (Guest, Host, Architect) are issued for your team to test with before Cradle provisioning begins.
Phase 03 · Cradle provisioning
Follows Cradle provisioning — see that page for the per-operator five-step ceremony.
Phase 04 · Data ingestion & Pearl training
Data sources named
You list the systems the Pearls will read from (CRM, ERP, ticketing, document store, meeting recordings). Nebbos maps each to an ingestion connector.
Row-level scope defined
For each system, you name which rows / documents each department’s Pearl can see. Row-level isolation is enforced from the moment of ingestion, not applied later.
Pearl training
Each department’s Pearl is trained on 20–100 yes/no decisions from your team. The Pearl asks; you answer; the decisions become the memory registers the Pearl reasons from.
Phase 05 · Approval-graph configuration
Approval flows named
For each operational decision that needs human approval (contract signature, refund issue, code deployment, task escalation), you name the tier gate and the human role that approves at that tier.
Graph configuration
The onboarding team configures the approval graphs in the platform. Each graph is a sequence of steps with per-step tier requirements. Configuration takes 1–3 hours per graph.
End-to-end test
Walk a real (test-scoped) request through the graph. Every attested approval lands in the audit chain. If the chain doesn’t hold end-to-end, the graph doesn’t ship.
Phase 06 · Production sign-off
The final phase is a written attestation from your security officer that the deployment meets your internal control requirements. Nebbos does not consider a deployment production-ready until you sign this. We do not “go live” and then patch — every gate above must be cleared before Phase 06 starts.
What we don’t do
- We don’t manage your identity provider on your behalf.
- We don’t classify your data for you — you name the row-level scopes.
- We don’t retrain the Pearls without your explicit approval; each retraining is an audited event.
- We don’t ship a deployment that hasn’t cleared Phase 06 sign-off, regardless of contract urgency.
Getting help
Your named deployment lead is available in the shared channel throughout onboarding. For post-onboarding questions, see Admin guide and FAQ.