Responsibility matrix
Who does what in each of the five models.
Who does what, per model. G = Galtea, C = Customer, G+C = shared, with the split
described in the notes.
Documentation Index
Fetch the complete documentation index at: /llms.txt
Use this file to discover all available pages before exploring further.
Who does what in each of the five models.
| Responsibility | 1. Shared SaaS | 2. Enterprise org | 3. Private tenant |
|---|---|---|---|
| Infrastructure | |||
| Provision cloud account | G | G | G |
| Provision and patch Kubernetes cluster | G | G | G |
| Provision database | G | G | G |
| Provision object storage | G | G | G |
| Network design and firewall rules | G | G | G+C |
| DNS and TLS certificates | G | G | G |
| Platform | |||
| Install the platform | G | G | G |
| Apply upgrades | G | G | G |
| Ship fixes and new versions | G | G | G |
| Capacity sizing and scaling | G | G | G |
| Configure LLM providers and models | G | G | G+C |
| Identity | |||
| Operate the identity provider | G | G | G |
| Register Galtea in your IdP | n/a | C | C |
| Map groups to roles | n/a | G+C | G+C |
| Manage users and roles in the product | C | C | C |
| Manage and revoke API keys | C | C | C |
| Data | |||
| Database backups and restore testing | G | G | G |
| Data retention configuration | G | G | G+C |
| Deciding what test data is uploaded | C | C | C |
| Security | |||
| Platform vulnerability patching | G | G | G |
| Cluster and OS patching | G | G | G |
| Web application firewall | G | G | G |
| Egress allowlist definition | G | G | G+C |
| Credentials for your product endpoints | C provides, G stores | C provides, G stores | C provides, G stores |
| Penetration testing coordination | G+C | G+C | G+C |
| Operations | |||
| Monitoring and alerting | G | G | G |
| First-line incident response | G | G | G |
| Root-cause analysis of product bugs | G | G | G |
| Status communication | G | G | G |
| Responsibility | 4. In your cluster | 5. Self-hosted |
|---|---|---|
| Infrastructure | ||
| Provision cloud account | C | C |
| Provision and patch Kubernetes cluster | C | C |
| Provision database | C | C |
| Provision object storage | C | C |
| Network design and firewall rules | C | C |
| DNS and TLS certificates | C | C |
| Platform | ||
| Install the platform | G | C |
| Apply upgrades | G | C |
| Ship fixes and new versions | G | G |
| Capacity sizing and scaling | G+C | C |
| Configure LLM providers and models | G+C | C |
| Identity | ||
| Operate the identity provider | C | C |
| Register Galtea in your IdP | C | C |
| Map groups to roles | C | C |
| Manage users and roles in the product | C | C |
| Manage and revoke API keys | C | C |
| Data | ||
| Database backups and restore testing | C | C |
| Data retention configuration | G+C | C |
| Deciding what test data is uploaded | C | C |
| Security | ||
| Platform vulnerability patching | G | G ships, C applies |
| Cluster and OS patching | C | C |
| Web application firewall | C | C |
| Egress allowlist definition | C | C |
| Credentials for your product endpoints | C provides, G stores | C |
| Penetration testing coordination | G+C | C |
| Operations | ||
| Monitoring and alerting | G+C | C |
| First-line incident response | G | C |
| Root-cause analysis of product bugs | G | G, with logs from C |
| Status communication | G | C internally |