The three environments
We provide each customer with its own dedicated, containerised B-SAFE instance. That instance comes with three environments:
| Environment | What it is for |
|---|---|
| Test | Building and trying out configuration changes, checking a new form or workflow end to end, and testing integrations before anything reaches live users. This is also where new releases are available first. |
| Training | Running training sessions and letting new users practise, on a version of the system that matches what they will actually see in Production. |
| Production | The live service your staff use day to day. This is the environment covered by the availability, backup and recovery commitments in your contract. |
How Test and Training are set up
Test and Training are set up as copies of the configured Production instance. What is copied is the configuration — your forms, workflows, rules, templates and organisational structure — so that the environments behave like the live system.
Each of the three environments has:
- its own access. Being an administrator in Test does not make you an administrator in Production, and access is granted per environment.
- its own single sign-on registration. Where you federate identity with Microsoft Entra ID using SAML 2.0 or OpenID Connect, each environment is registered separately, so you can control who can sign in to which environment using your own groups and conditional access policies.
- its own notification routing. Notifications generated in Test and Training are routed separately from Production, so that test and training activity does not send emails or alerts to real staff. You choose the mechanism: notifications in a non-production environment can be suppressed altogether, redirected to a nominated test mailbox, or delivered only to accounts registered in that environment.
Data in non-production environments
Production data is never copied into a non-production environment. That applies to your Test and Training environments and to our own development and testing, where we use synthetic or anonymised data only.
You choose what your Test and Training environments hold: synthetic data that we provide, anonymised data that you load yourself, or an empty configured instance.
If you need realistic-looking data for training, use anonymised or synthetic records. Do not copy live records into Test or Training.
Moving configuration between environments
B-SAFE is configured rather than coded. Forms, workflows, rules, notification and report templates, permissions and organisational structures are all configuration objects, and all of them can be changed inside the system without contacting us.
That means configuration is promoted between environments rather than rebuilt in each one. The normal route is:
Test → Training → Production
You build and check a change in Test, use Training to prepare and train people on it, and promote the same configuration to Production. Nothing is re-keyed by hand, so what you tested is what goes live.
Every promotion is recorded in the full audit trail — when, who, what and how it changed — alongside every other change in the system. Audit data is retained for at least 12 months and you have real-time access to it, including a record of our activity as well as your own.
You choose who runs the promotion: your own administrators can run it from within the system, or you can ask us to run it for you.
The API sandbox
An API sandbox and test environment is part of the service. You can develop and test an integration against the API — pulling entries from each module using filters, with API keys issued at different permission levels and restricted to particular modules or functions — without pointing it at live data. API documentation is published in OpenAPI (Swagger), HTML, ODF and PDF.
API keys are issued separately for each environment, and the sandbox has its own base URL.
Releases and release testing
B-SAFE has one major release a year and weekly updates, with critical updates applied no later than the next working day. Standard releases and updates do not require planned downtime. We notify customers of releases by email and through the support portal.
Releases reach Test before Production, so you can check your own configuration and integrations against a new version first. There is no fixed interval: you decide how long a release stays in Test and when it is applied to Training and Production. Because standard releases and updates do not require planned downtime, waiting longer does not mean booking a maintenance window.
Where a release will require you to change your own configuration, we tell you ahead of the release rather than with it.
Who does what
You (customer administrators)
- configure forms, workflows, rules, templates, permissions and organisational structure, in the system, without contacting us
- decide when a change moves from Test to Training to Production
- manage and provision your own user accounts, in each environment
- decide what data is loaded into Test and Training
Us (Bondap)
- provision the three environments as part of setting up your instance
- run the platform, apply releases, and notify you of them
- hold no standing access to customer data. Privileged access is granted only for a specific approved task, is time-limited, and every use is recorded in an audit log
Questions
Raise a ticket through the support portal, or email gc@bondap.com.
Contact: gc@bondap.com
© BONDAP LTD. This document is the property of Bondap and is published for information only. It may not be copied, reproduced, adapted, distributed or used for any purpose without our prior written consent.