> ## Documentation Index
> Fetch the complete documentation index at: https://docs.galtea.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Responsibility matrix

> Who does what in each of the five models.

Who does what, per model. **G** = Galtea, **C** = Customer, **G+C** = shared, with the split
described in the notes.

## Models 1 to 3: Galtea operates the infrastructure

| Responsibility                         | 1. Shared SaaS       | 2. Enterprise org    | 3. Private tenant    |
| -------------------------------------- | -------------------- | -------------------- | -------------------- |
| **Infrastructure**                     |                      |                      |                      |
| Provision cloud account                | G                    | G                    | G                    |
| Provision and patch Kubernetes cluster | G                    | G                    | G                    |
| Provision database                     | G                    | G                    | G                    |
| Provision object storage               | G                    | G                    | G                    |
| Network design and firewall rules      | G                    | G                    | G+C                  |
| DNS and TLS certificates               | G                    | G                    | G                    |
| **Platform**                           |                      |                      |                      |
| Install the platform                   | G                    | G                    | G                    |
| Apply upgrades                         | G                    | G                    | G                    |
| Ship fixes and new versions            | G                    | G                    | G                    |
| Capacity sizing and scaling            | G                    | G                    | G                    |
| Configure LLM providers and models     | G                    | G                    | G+C                  |
| **Identity**                           |                      |                      |                      |
| Operate the identity provider          | G                    | G                    | G                    |
| Register Galtea in your IdP            | n/a                  | C                    | C                    |
| Map groups to roles                    | n/a                  | G+C                  | G+C                  |
| Manage users and roles in the product  | C                    | C                    | C                    |
| Manage and revoke API keys             | C                    | C                    | C                    |
| **Data**                               |                      |                      |                      |
| Database backups and restore testing   | G                    | G                    | G                    |
| Data retention configuration           | G                    | G                    | G+C                  |
| Deciding what test data is uploaded    | C                    | C                    | C                    |
| **Security**                           |                      |                      |                      |
| Platform vulnerability patching        | G                    | G                    | G                    |
| Cluster and OS patching                | G                    | G                    | G                    |
| Web application firewall               | G                    | G                    | G                    |
| Egress allowlist definition            | G                    | G                    | G+C                  |
| Credentials for your product endpoints | C provides, G stores | C provides, G stores | C provides, G stores |
| Penetration testing coordination       | G+C                  | G+C                  | G+C                  |
| **Operations**                         |                      |                      |                      |
| Monitoring and alerting                | G                    | G                    | G                    |
| First-line incident response           | G                    | G                    | G                    |
| Root-cause analysis of product bugs    | G                    | G                    | G                    |
| Status communication                   | G                    | G                    | G                    |

## Models 4 and 5: you operate the infrastructure

| Responsibility                         | 4. In your cluster   | 5. Self-hosted      |
| -------------------------------------- | -------------------- | ------------------- |
| **Infrastructure**                     |                      |                     |
| Provision cloud account                | C                    | C                   |
| Provision and patch Kubernetes cluster | C                    | C                   |
| Provision database                     | C                    | C                   |
| Provision object storage               | C                    | C                   |
| Network design and firewall rules      | C                    | C                   |
| DNS and TLS certificates               | C                    | C                   |
| **Platform**                           |                      |                     |
| Install the platform                   | G                    | C                   |
| Apply upgrades                         | G                    | C                   |
| Ship fixes and new versions            | G                    | G                   |
| Capacity sizing and scaling            | G+C                  | C                   |
| Configure LLM providers and models     | G+C                  | C                   |
| **Identity**                           |                      |                     |
| Operate the identity provider          | C                    | C                   |
| Register Galtea in your IdP            | C                    | C                   |
| Map groups to roles                    | C                    | C                   |
| Manage users and roles in the product  | C                    | C                   |
| Manage and revoke API keys             | C                    | C                   |
| **Data**                               |                      |                     |
| Database backups and restore testing   | C                    | C                   |
| Data retention configuration           | G+C                  | C                   |
| Deciding what test data is uploaded    | C                    | C                   |
| **Security**                           |                      |                     |
| Platform vulnerability patching        | G                    | G ships, C applies  |
| Cluster and OS patching                | C                    | C                   |
| Web application firewall               | C                    | C                   |
| Egress allowlist definition            | C                    | C                   |
| Credentials for your product endpoints | C provides, G stores | C                   |
| Penetration testing coordination       | G+C                  | C                   |
| **Operations**                         |                      |                     |
| Monitoring and alerting                | G+C                  | C                   |
| First-line incident response           | G                    | C                   |
| Root-cause analysis of product bugs    | G                    | G, with logs from C |
| Status communication                   | G                    | C internally        |

## Notes on the shared items

**Network design in a private tenant.** Galtea designs and operates the tenant network.
You decide how your side reaches it (VPN client, site-to-site routing peer, private link,
or peering) and which of your IP ranges are allowed. Galtea implements what you decide.

**Group-to-role mapping in federated mode.** You own the groups in your directory. Galtea
owns which product permissions each role carries. The mapping between them is agreed once
and then driven entirely by your directory: a membership change on your side takes effect at
the user's next sign-in.

**LLM provider configuration in a private tenant.** Galtea configures the gateway. You
decide whether inference runs on Galtea's provider accounts or on yours, and whether the
model set is restricted to an approved subset.

**Egress allowlist in a private tenant.** You tell Galtea which of your endpoints the platform
must call. Galtea adds them to the allowlist. Nothing else is reachable.

**Product bugs in a self-hosted install.** Galtea fixes bugs and ships a version regardless
of model. In a self-hosted install Galtea cannot see your environment, so reproducing the
bug depends on the logs and version information you provide, and applying the fix depends on
you upgrading.

## The one-sentence version

In models 1 and 2 you manage users and test data, and nothing else. In model 3 you
additionally decide the network and identity boundary while Galtea still operates
everything. In model 4 you operate a platform that Galtea builds and supports.
