Shared responsibility

Who owns what — written down, before there is an incident

A finance-grade platform should never be unclear about responsibility. This matrix is the same one we sign into MSAs, walk through with auditors, and reference in incident reviews.

Matrix items

21

Across nine domains

ADmetric-owned

10

Engineered, cannot be opted out

Customer-owned

9

With templates & playbooks

Versioned

Quarterly

Changes published on /change-notice-policy

Responsibility matrix

AreaControlOwner
IdentitySSO / IdP integration (SAML, OIDC)Customer
IdentityWebAuthn enforcement for privileged pathsADmetric
IdentityRole assignment inside workspaceCustomer
DataEncryption in transit / at restADmetric
DataClassification of customer-provided PIICustomer
DataCross-region replicationADmetric
ControlsGuardrails-as-code (caps, kill switches)ADmetric
ControlsPolicy authoring & reviewCustomer
PayoutsTreasury queue + 2-of-3 approvalADmetric
PayoutsBank account ownership & FX corridor selectionCustomer
PayoutsPlatform-side spend reconciliationShared
ReliabilityRTO/RPO per service tierADmetric
ReliabilityCustomer DR drills (tabletops)Customer
AuditImmutable audit log (Merkle ledger)ADmetric
AuditAuditor walk-through and evidence accessShared
Ad platformsPlatform terms complianceCustomer
Ad platformsAPI rate limit managementADmetric
PrivacyDPA, sub-processors registerADmetric
PrivacyData subject requests (DSR) intakeCustomer
Incident responseDetection & containment of our infrastructureADmetric
Incident responseCustomer-side coordination & commsCustomer

How we keep this honest

  • Every line maps to a control in /controls, an owner in /access-paths, and a runbook in /runbooks.
  • Material changes require CAB approval and a 90-day notice on /change-notice-policy.
  • We bind this matrix into the MSA; ambiguity is treated as our failure during incidents.
  • Auditor walk-through uses this page as the index.