Controlled Work

Gesso Federal collaborates with your security team and works in your enclave.

For each approved deployment, your Operations Lead runs the response or reporting workflow named in the scope using client-issued access and only the services approved for that contract.

CUI boundary Client-managed environment Client-issued access Approved processing services

The working boundary

Your Operations Lead stays responsible for the work inside the boundary you approve.

Standard Work

Federal paperwork without controlled information.

Handled through Gesso Federal's approved ordinary systems.

Controlled Work

Federal paperwork involving CUI or covered defense information.

Handled through the client-managed environment and any external processing service expressly approved for that deployment.

Controlled files and persistent working records stay in the client-managed environment. Only information needed for the approved workflow may pass through its documented processing connection. Controlled content does not enter Gesso Federal's ordinary commercial systems.

Who does what

Your company controls the environment. Your Operations Lead keeps the paperwork moving.

Your security team controls

  • The environment and approved processing services
  • Identities, access, and retention
  • Assessment records and the incident route

Gesso Federal handles

  • Workflow configuration inside that boundary
  • Coordination, drafting, and checks
  • The finished files and review handoff

How work begins

Define it. Test it. Then run it.

We start with the workflow and contract requirements, not the controlled files.

01

Define the work and boundary.

We document the work, data, decision owners, environment, application categories, external processing services, access, and connections with your team.

02

Configure and test it.

Inside the blank client environment, we return one consolidated administrator list, complete the remaining setup, and test the exact workflow with invented files. Only functions that pass are enabled.

03

Begin the approved work.

Your security owner reviews the results and any unresolved exception before live work begins. Routine work then continues under that authorization.

The exact boundary

Your security approval covers one defined deployment and workflow.

Your contract and security owners decide how Gesso Federal and each external service fit the contract and CMMC assessment scope, and which system, asset, network, responsibility, incident, and retention records must be updated. Another review is needed only for a material change to the approved boundary or authority.

Export-controlled technical data

Export-controlled technical data requires separate written approval from your export-control owner covering the people, locations, systems, authorization, and handling route before work begins.

Classified information

Gesso Federal does not handle classified information.

For your security team

A clear record of the working boundary.

The Controlled Work guide explains the data route, application and processing-service review, responsibilities, named access, one consolidated IT action list, testing, changes, incidents, and offboarding.

Download the guide

Start with the work

Tell us which workflow contains CUI and what the contract requires.

Hold the controlled files until your security team approves the working boundary and processing route.

Book a Controlled Work Fit Call