Map responsibility at every transition
By the end, explain the diagram in your own words, solve the case and justify the correction.
Prerequisites : Hot, warm and cold wallets · From signing to settlement
Level 2 · Intermediate →Reading path · 29 / 35 · Intermediate
An operating model assigns decisions, execution and evidence across a service.
The essentials
An operating model assigns decisions, execution and evidence across a service. Start from the client instruction and follow the asset until the client ledger is updated. Technology, operations, risk and product teams need a shared definition of each state: received, approved, signed, broadcast, confirmed and reconciled.
How it works
For every transition, identify an owner, an independent check, a deadline and an exception path. A service diagram should show external dependencies such as signing providers, blockchain nodes and banking rails. A provider can execute a task while the institution retains responsibility for monitoring and escalation.
What to watch
Define who can change limits and who approves those changes. Separate routine processing from emergency intervention. Measure both completed instructions and unresolved exceptions: a high completion rate can hide a small number of old, material breaks. Review access and handovers when teams or suppliers change.
Build your analysis
A withdrawal crosses four teams: client service receives it, operations validates the instruction, a separate signing function authorises it, and accounting reconciles it. Draw the handover between each pair. At every handover, state what the receiver must know before accepting ownership. A message saying “done” is insufficient unless it names the completed state.
Extend the workshop
For the workshop, produce a one-page responsibility map. Include an absent approver, an out-of-hours request and a provider outage. Explain who can stop processing, who investigates the queue and what evidence permits resumption. Compare your map with the transaction states rather than with job titles alone.
Understand the details
A responsibility matrix is useful only when it resolves actual decisions. For a delayed withdrawal, name the person who investigates, the person who may suspend new withdrawals and the person who communicates verified information. Keep an instruction identifier that links the approval, signature and ledger entry without putting personal client data on-chain.
Boundaries and common mistakes
A role label is not evidence of independence. Two approvers using the same compromised account do not create two independent checks. Approval coverage must also exist outside normal office hours if the service continues operating.
The mechanism at a glance
- Instruction
- Owner and check
- Execution evidence
- Exception closure
Apply the lesson to a case
A fictional service processes transfers all weekend, but its exception team returns on Monday. A Friday instruction is approved yet never broadcast. Draft a handover with its last verified state, evidence, owner and next review time. Decide whether the client should see completed, pending or failed.
Approval does not prove broadcast or settlement. The handover should identify the pending state and an accountable person with authority to investigate; it must not invent a failure or promise completion.
Prepare a correction note
Describe the passage and the proposed correction. This creates a local note for you to share; it sends nothing. Do not include personal or confidential information.