Originally written in French. Translated by AI — the meaning has been preserved, not the prose.
Main idea
When a large organization asks that a payroll product's database stay in its own Azure subscription, the vendor first hears doubt: we know perfectly well how to host a database, why the mistrust?
That is not the question being asked. The question isn't "are you capable of hosting my data properly?" but "does my data stay under my organization's control?".
What the customer wants to apply is its network rules, its security policies, its keys, its inventory mechanisms, its internal standards — and to be able to tell its CISO, its auditor or its organization: this data stays with us.
Why it matters
Confusing competence with control produces ineffective answers. To a question about control you reply with certifications, incident history, operational quality — and the customer stays stuck, because you answered beside the point.
It also says where to look for the solution: not in a better proof of competence, but in sharing control, whose level remains to be calibrated.
Nuances and limits
Some requests really are doubts about competence, and evidence settles them. Both exist and look alike on the surface.
And the control being demanded doesn't always mean hosting: a dedicated region, customer-managed keys or a single-tenant environment are sometimes enough.
Open questions
- What phrasing, in pre-sales, lets you tell a control requirement apart from a doubt about competence?