Automation Owner
Responsibility: Owns the overall automation outcome, scope, health, maintenance, and lifecycle.
Decisions: Proposes changes, coordinates reviews, responds to degradation, and ensures ownership remains current.
Evidence: Version history, health records, change requests, owner reviews, retirement records.
Workflow Owner
Responsibility: Owns how the automation fits into the defensive process, queue, ticket, and analyst workflow.
Decisions: Approves workflow-state logic, routing design, fallback, and operational handoffs.
Evidence: Workflow maps, routing decisions, exception history, SLA and state records.
Control Owner
Responsibility: Owns the intended defensive control objective the automation supports.
Decisions: Defines what success means and whether the automation still supports the control as designed.
Evidence: Control intent, control test results, evidence requirements, residual gaps.
Evidence Owner
Responsibility: Ensures records are attributable, complete, current, and available for review.
Decisions: Defines evidence fields, retention expectations, source quality, and evidence-health triggers.
Evidence: Log schema, source inventory, evidence completeness metrics, exception evidence.
Platform Owner
Responsibility: Owns the fictional automation platform, integration reliability, permissions, and service health.
Decisions: Approves platform changes, monitors dependencies, and manages technical disable or degraded states.
Evidence: Platform health, dependency status, permission reviews, availability records.
Analyst / Operator
Responsibility: Uses the automation output, applies judgment, records overrides, and reports workflow problems.
Decisions: Accepts, rejects, corrects, or escalates automation-supported outputs within assigned authority.
Evidence: Review notes, overrides, reason codes, analyst feedback, escalations.
Risk / Governance Owner
Responsibility: Owns acceptance of residual risk, policy alignment, exception oversight, and material governance decisions.
Decisions: Approves exceptions, material scope changes, risk acceptance, and continued operation under known gaps.
Evidence: Exception approvals, risk decisions, governance reviews, review dates.
Authorized Approver
Responsibility: Provides explicit decision authority at defined human-gated workflow points.
Decisions: Approves, rejects, escalates, or requests more evidence for authority-sensitive transitions.
Evidence: Approver identity, evidence package, decision, rationale, timestamp.
Change Reviewer
Responsibility: Independently reviews proposed automation changes before they become active.
Decisions: Checks scope, permissions, failure behavior, metrics, evidence, and rollback or fallback readiness.
Evidence: Change review record, test summary, approvals, conditions, effective version.
Business / Service Owner
Responsibility: Provides context on business criticality, operational dependencies, acceptable disruption, and service ownership.
Decisions: Confirms whether automation behavior still fits the service's business context.
Evidence: Service mapping, dependency statement, ownership confirmation, business-impact notes.