Scope matrix
Four workstreams to check for a project in Business Bay.
For Business Bay, this planning route connects Security controls, Cloud workload planning, Access and attendance and service-level definition. It is not a fixed package: the final quotation follows the real site, users, existing systems, access constraints, timing and support responsibility.
01Security controls
Map internet exposure, user groups, privileged access, endpoints, remote access, firewall policy, logging and the systems that would create the highest business impact if unavailable. The scope should connect preventive controls with monitoring, incident response and ownership instead of buying independent security products without an operating model. Handover readiness: Define the diagrams, configuration records, asset list, warranty documents, test evidence and credential-transfer method required at completion.
Review cybersecurity →02Cloud workload planning
Inventory workloads, identities, licences, integrations, data location, internet dependence, security controls, backup and support responsibilities before selecting a cloud path. The goal is to identify what can move, what should remain local and what must be redesigned so migration does not simply transfer unresolved technical debt. Continuity readiness: Record current backups, rollback options, communication needs and the safest sequence of changes so business-critical services remain protected during implementation.
Review cloud solutions →03Access and attendance
Identify doors or controlled points, user groups, credentials, attendance reporting, controller topology, network connectivity, power, emergency behavior, integration needs and administrator roles. The scope should explain how users are enrolled, who can change permissions and how access records will be retained and supported. Commercial readiness: Confirm quantities, preferred brands or acceptable alternatives, warranty expectation, quotation format and target delivery window before commercial comparison begins.
Review access control →04Service-level definition
State covered services, operating hours, severity levels, response targets, escalation contacts, communication method, maintenance windows, exclusions and reporting. A useful SLA translates business criticality into an agreed support process and avoids ambiguous expectations during incidents or planned work. Support readiness: Identify critical services, business hours, escalation contacts, remote-access policy and the systems that require preventive or recurring support after go-live.
Review service-level support →