Tier 1: Provider
Provides the model and service under published capabilities and limitations. It does not own the enterprise's decision to use the recommendation in procurement.
CONSTRUCTED EXAMPLE
A generic enterprise procurement team is preparing an agent that checks vendor submissions and recommends whether a human reviewer should escalate a package.
Free to read and cite with attribution to Sougata Roy and sougataroy.com. Do not republish, rebrand, or claim authorship of any framework, term, or model as your own.
Filled accountability map
This scenario is constructed for explanation. It is not a real organization and is not drawn from an engagement.
Tier 1: Provider
Provides the model and service under published capabilities and limitations. It does not own the enterprise's decision to use the recommendation in procurement.
Tier 2: Control infrastructure
Provides the registered identity, configured permissions, audit trail, and access controls. It enforces what the organization configures, not what the organization intended but never recorded.
Tier 3: Deploying organization
Authorizes the purpose, permitted scope, prohibited actions, human review point, named Consequence Owner, and deployment decision. Those choices are recorded before production use.
Output
A completed map showing the gap between platform controls and organizational accountability.
How to use this page
Compare this completed map with the primary framework, then create a map for a real deployment. The example demonstrates the accountability boundary; it does not replace organization-specific authorization.