What was said
What this says
Current to 10 Oct 26Nadia Osei, IT Security Lead, offered two slots and set four conditions: written answers in the questionnaire, evidence on access control, written residency, and the diagram sent ahead. She gave no sign-off date.
Ask: Nadia wants the security session treated as evidence gathering. She asks for permission inheritance from source systems, who at BB-Demo can see inside the Snowflake account, and where processing happens, not just storage.
Customer view: She needs everything in writing for the audit trail. She cannot set a sign-off date until the capacity providers have seen the pack.
Next: Hannah Lowe should confirm a slot, send the questionnaire answers and the diagram ahead, and check uncertain points with the security colleague.
The thread
Updated 9 Oct 26Messages
- Hannah Lowe 17 Nov 2025 11:03Hi Nadia, Thanks for the time on our call. To be precise about what we agreed, I'll run a working session on how the brain is built and run for Fenmoor: the architecture, access control, and where your data sits. The short answer on residency is that the brain runs inside your own Snowflake account; the longer answer is easier to show on a diagram than in an email, so I'll bring one. Could we find an hour either later this week or early next week? It would help if you could send me your supplier questionnaire beforehand, so I can answer in the format you need and not just talk around it. Anything I'm not certain of I'll check with our security colleague and put in writing, rather than answer on the spot. Is there anyone else at Fenmoor who should join? Whoever deals with the capacity providers' audits might want to hear it first-hand. Thanks, Hannah
- Nadia Osei 19 Nov 2025 11:51Hello Hannah, Thank you, this is helpful. I can offer Tuesday at 14:00 or Wednesday at 10:30, whichever suits you. A few points so we use the hour well: First, I will send the questionnaire tomorrow. Please answer in the document itself. I'll need that in the questionnaire, not only said in the session, for the audit trail. Second, on access control, can you evidence how permissions are inherited from the source systems into the brain, and who at BB-Demo can see anything inside our Snowflake account? Third, on residency, please confirm in writing where processing happens, not just where storage sits. Fourth, I would like the architecture diagram to be sent ahead of the session as well as shown during it. One caution: I can't set a sign-off date until the capacity providers have seen the pack, so please treat this session as evidence gathering and not as approval. Kind regards, Nadia