doc/security/dedicated_for_government_shared_responsibility_model.md
{{< details >}}
{{< /details >}}
GitLab Dedicated for Government maintains a FedRAMP Moderate Authorization that encompasses a shared responsibility model with federal agencies. Federal agencies must understand their responsibilities when operating a Dedicated for Government GitLab instance, and which responsibilities they can inherit from the GitLab authorization. This document helps you understand:
For a detailed breakdown of customer responsibilities tied to NIST 800-53 controls,
request the GitLab Dedicated for Government FedRAMP package using the
FedRAMP package request form.
The GitLab package ID is FR2411959145. The Control Implementation Summary/Customer Responsibility
Matrix Excel template, available in the FedRAMP package on Connect.gov, is essential for any
federal agency that needs to understand their responsibilities.
The GitLab Dedicated for Government secure configuration guide builds on this responsibility guide with specific configuration guidance and mappings to GitLab documentation.
The following sections help federal agencies understand the broad responsibilities covered by customers and GitLab in a standard GitLab Dedicated for Government deployment. Each section is organized by functional area and outlines customer and GitLab-owned responsibilities. Work with your GitLab partners to validate responsibilities as applicable to your specific deployment.
Optional features and customizations that may affect customer responsibilities:
GitLab is responsible for the following:
Customers are responsible for the following:
GitLab is responsible for the following:
Customers are responsible for the following:
Customers must enable only the GitLab Duo Agent Platform capabilities GitLab has confirmed are authorized for use within Dedicated for Government: Duo Classic features, Agentic Chat, and foundational agents. GitLab Duo Agent Platform flows and external agents require self-managed CI/CD runners and are not authorized for use within Dedicated for Government.
GitLab is responsible for the following:
Customers are responsible for the following:
GitLab is responsible for the following:
Customers are responsible for the following:
GitLab is responsible for the scanning and patching of the following:
Customers are responsible for the following:
GitLab is responsible for the following:
Customers are responsible for the following:
GitLab is responsible for the following:
Customers are responsible for the following:
Federal agencies may be required to share code publicly, for example, under the SHARE IT Act. By default, GitLab Dedicated for Government restricts the public visibility level for the instance. A top-level administrator must turn on public visibility before any group or project can be made public. For configuration steps, see restrict visibility levels and project and group visibility.
GitLab is responsible for the following:
Customers are responsible for the following: