OUR INTEGRATION MODEL
Your systems.
Our work, under your direction.
We design, build, and maintain connections as a contractor authorized by your business. You retain control of your environments, users, client-owned applications, and credentials.
WHY CUSTOMER OWNERSHIP MATTERS
The connection should stay with the business.
An office may need a workflow that its existing software does not provide out of the box. A customer-owned integration can address that specific need while keeping the accounts, operating decisions, and agreed deliverables with the business.
This is our delivery model where the vendor supports it. It is not a universal platform requirement or a substitute for vendor approval. Before a build, we confirm the permitted application type, account eligibility, required permissions, and who controls the software that will actually run.
AGREED DATA FLOW / SUBJECT TO VENDOR REQUIREMENTS
Your administrators control vendor accounts and credentials. Hosting control is documented separately.
WHO CONTROLS WHAT
Separate ownership
from the work performed.
Registering an app and owning the software behind it are different. We make both explicit in the agreement.
| Part of the engagement | The client controls | Tack does |
|---|---|---|
| Business and software accounts | The client owns its vendor relationships and controls its tenant configuration, users, billing, and account recovery. | We assess requirements and implement scoped changes through the access the client and vendor permit. |
| Developer registration and app | The client registers and controls its own developer portal app where that model is supported and approved. | We guide registration, document required scopes, and build or maintain the agreed client-owned application. |
| Credentials and authorization | The client’s administrator manages credential creation, storage, rotation, access approval, and revocation. | We document access needs and use only the vendor-permitted contractor access assigned for the project. |
| Code, configuration, and runtime | The client approves the hosting arrangement and agreed code, configuration, and handoff rights. The agreement identifies the actual hosting account owner and administrators. | We design, build, test, document, and maintain the scoped work. Hosting may be client-managed or provided under a separate agreement where vendor requirements permit. |
| Data and operations | The client approves the data involved, the permitted destination, the office owner, and the operating requirements. | We apply scoped validation, monitoring, exception handling, and training within the vendor’s data-use and retention rules. |
ACCESS HAS A START AND AN END
Authorize. Review. Revoke.
A written scope identifies the work, the people allowed to perform it, and how access ends.
Authorize the agreed work.
Confirm the vendor’s supported route and any required approval. Your administrator completes authorization and assigns the narrowest permitted contractor access. Passwords and secrets do not belong in a consultation request.
Review while work is active.
Maintain an access inventory without copying secret values into it. Record purpose, permissions, administrators, renewal dates, data destinations, and changes. Revisit access when scope or staffing changes.
Revoke and hand over.
Follow the vendor’s process to remove users or grants, disconnect apps, and rotate or revoke credentials where required. Verify that access stops, transfer the agreed documentation, and complete required data deletion.
A DEFINED OPERATING ARRANGEMENT
What this model requires.
- Actual ownership and control of the application and runtime must match the vendor’s requirements and the agreement—not just a registration made in the client’s name.
- A vendor-permitted route for any connection to third-party systems. Customer app keys must not be passed to uncontrolled third-party applications to bypass vendor requirements.
- Separate customer environments and access. No pooling of customer data, resale of API access, or reuse of one client’s credentials for another.
- A data-handling plan that checks allowed uses, destinations, storage, retention, and deletion before data is transferred or retained.
- A written agreement covering deliverables, intellectual property, responsibilities, confidentiality, support hours, and offboarding.
Clients are responsible for authorizing and managing access in accordance with their software vendors' applicable terms and policies.
DEFINE THE WORK BEFORE THE BUILD
Map the right access path first.
Tell us what your team is working through, which tools are involved, and what you want to happen next.