sourcing · version 2026.1
Internal Team vs MSP Responsibility Model
A retained-organization view that separates internal accountability from delegated provider execution.
Accessible diagram transcript
Objects
- Internal service owner: Outcome accountability (Service ownership)
- Internal architecture authority: Technical decisions (Authorities)
- Internal risk authority: Risk acceptance (Authorities)
- Vendor management: Performance and escalation (Governance)
- Managed service provider: Delegated build / run execution (Providers)
- Provider evidence: Performance, controls, actions (Operations)
Directed relationships
- owner → msp: delegates (handoff)
- architecture → msp: sets constraints (authority)
- risk → msp: sets conditions (authority)
- msp → evidence: reports (handoff)
- evidence → vendor: performance (handoff)
- owner → evidence: retained oversight (accountability)
When to use it
Use before finalizing an MSP scope, RFP or operating responsibility matrix.
What to challenge
- Separate accountable authority from delivery execution.
- Make every important handoff directional and reviewable.
- Treat this reference pattern as a starting point, not a prescription.
Adapt it responsibly
- Rename functions to match the organization vocabulary.
- Remove elements that are genuinely out of scope.
- Validate decision rights and handoffs with accountable stakeholders.
Model contents
6 objects and 6 directed relationships. Every object keeps a stable semantic ID.
One model, multiple representations
The browser view and editable file are generated from the same canonical graph, so labels, roles and relationship direction stay aligned.
Clear visual grammar
Shape, color and connector style distinguish actors, governance, authorities, services, engineering, operations and providers.