Tarly logo Tarly · Secure Configuration Guide Trust Center →

Tarly Cowork Secure Configuration Guide

Recommended security configuration for agency administrators and privileged users of the Tarly Cowork SaaS offering.

FedRAMP package ID: FR2628650874

Version 1.2 · Published July 17, 2026 · Updated August 17, 2026 · Owner: Tarly Security

Use of this guide. Apply this baseline before placing federal information in Tarly Cowork, after any administrative change, and during each access review. Agency policy and an agency authorization may require stricter settings. Questions and access changes should be sent to security@tarly.co.

1. Administrative account model

Tarly Cowork uses two administrative layers:

No customer user may self-promote to platform administrator. Procurement-file roles may be changed only by a member with the members:manage permission.

2. Securely provision and access administrative accounts

  1. Designate named individuals; never use shared or group credentials.
  2. Use an agency-controlled email address and an agency-approved device.
  3. Request platform-level access in writing from Tarly Security. Include the person's name, agency, official role, business need, approving official, requested duration, and whether access is emergency or routine.
  4. For procurement-file access, start with the least-privileged role in the matrix below. Assign Admin or CO only when the user must manage membership or modify all file content.
  5. Use agency-approved federated sign-in when it has been configured for the deployment. For password-based access, use a unique password of at least 15 characters stored in an approved password manager.
  6. Do not begin processing federal information until required agency authentication controls have been confirmed with Tarly Security.
  7. Verify the system-use notification and production hostname (https://gov.tarly.co) before signing in.

3. Recommended least-privilege roles

RoleRecommended useSecurity implications
AdminFile administrator who must manage members and all file content.Full create, update, delete, evidence upload, audit, settings, chat, and export privileges.
COContracting Officer responsible for the procurement file.Can manage members and all content; use only for accountable file owners.
Contract Specialist (CS)Staff who develop artifacts and evidence.Can create, change, and delete artifacts and upload evidence, but cannot manage members.
Program Manager (PM)Contributor who needs read access, chat, and exports.Cannot modify artifacts/evidence or membership.
LegalRead-only legal review and exports.Cannot send chat messages or modify content.
ApproverRead-only approval and audit review.Can read audit history and export but cannot modify content.
AuditorRead-only oversight and audit review.Can read audit history and export but cannot modify content.

4. Security-sensitive settings and operations

Settings reserved to the top-level platform administrator

Setting or capabilityHow it is controlledSecurity implication
Platform-administrator allowlistChanged only by Tarly Security through controlled service configuration; it is not customer self-service.Membership grants cross-workspace support visibility. Additions and removals require documented approval and must be reviewed promptly after personnel changes.
Cross-workspace support reviewAvailable only to allowlisted platform administrators; access is read-only and review events are audit logged.May expose customer conversations, evidence, and artifacts. Use only for an approved support, incident-response, or security-review purpose.
Top-level account disablementPerformed by Tarly Security after an authorized agency or internal request.Delays can extend access after a role change or departure; submit emergency deprovisioning requests immediately.
Global resource deletionRestricted to a platform administrator.Removal can affect shared reference material available across workspaces; verify scope, ownership, and retention requirements first.

Membership and role changes

Public conversation sharing

Evidence, external data, and exports

Platform-administrator review

Platform-administrator access can expose customer conversations and procurement-file content in a read-only support view. Tarly restricts this capability to approved administrators and records transcript and file review events. Agencies should require a documented support or security purpose before requesting such access.

5. Operating review checklist

6. Decommissioning

  1. Remove the user from every procurement file when access is no longer required. This immediately removes authorization to those files. For organization-wide separation, also request account disablement from Tarly Security; procurement-file removal alone does not end access to other files where the user remains a member.
  2. For platform administrators, send a written removal request to Tarly Security; Tarly removes the account from the administrator allowlist and confirms completion.
  3. Transfer accountable CO ownership before removing the departing CO.
  4. Inventory and disposition agency-held exports according to agency records schedules and information-handling policy.
  5. For full tenant or procurement-file closure, send an authorized data-removal request identifying the scope and required deadline. Tarly will confirm removal and any applicable backup-retention period.

7. Incident and support contacts

Security and urgent access removal: security@tarly.co

Sales and account coordination: cary@tarly.co

Include "SECURITY" in the subject for suspected compromise, unintended sharing, or emergency deprovisioning. Do not place passwords, tokens, CUI, or sensitive evidence in ordinary email.

8. Machine-readable guide and enhancement capabilities

The machine-readable baseline is available at /trust/secure-configuration-guide.json. It supplies stable setting identifiers, recommended values, comparison operators, current-value sources, provisioning defaults, and explicit capability limitations. A value that cannot be observed must be reported as not-observable; it must not be assumed compliant.

9. Revision history

VersionDateChange
1.2August 17, 2026No recommended secure default value was relaxed. Added the complete settings comparison and the all-security-settings export as authenticated capabilities, and pointed the platform-administrator, administrator-MFA, and public-sharing settings at the new observable sources that replaced their manual review paths.
1.1August 14, 2026No recommended secure default value was relaxed. Added stable setting IDs, comparison operators, current-value sources, provisioning defaults, machine-readable access, and a desensitized secure-default gap status.
1.0July 17, 2026Initial baseline for named platform administrators, least-privilege procurement-file roles, administrator provisioning and removal, public-sharing defaults, operating review, and decommissioning.