The Mission Shape
A shared service provider’s defining property is that its failures are not its own. A compromise of the platform is a compromise of every tenant on it, which means the quantity being defended is not the value of the provider’s data but the aggregate value of everybody else’s. Blast radius is the whole problem, and it is why this archetype marks a larger share of its estate as key terrain than any of the other nine.
Structurally the estate looks like a small number of very heavy elements: a federated trust fabric holding per-tenant identity, a multi-tenant platform, a segregated tenant data tier, and the platform administrators who can reach across all of it. The archetype starts in Deter because a provider is targeted for its position rather than for anything it did, and a provider that cannot demonstrate its posture to tenants does not get to keep them.
This is a composite, not an organization. Nothing on this page measures an agency, and the criticality and exposure figures below are the archetype’s own — useful for comparing shapes, useless as a statement about anybody.
What its key terrain typically is — 9 of 12 elements
How to read it. Nine of twelve elements are marked, the highest proportion of any archetype, and the reason is structural rather than alarmist: on a multi-tenant platform almost every element is shared, so almost every element is decisive for somebody. The platform administrators and the federated trusts are the two that decide the blast radius.
- T1Federated Trustsper-tenant IdP
- T4Shared Platformmulti-tenant
- T1Platform Adminsprivileged
- T5Tenant Datasegregated
- TXRecovery Vaultisolated · offline
- TXPlatform SOCmulti-tenant monitoring
- T7Platform Engineerstenant-wide privilege
- T8Regional Data Centersfacility · multi-tenant
- T9Infrastructure Suppliershardware · software
Key terrain is ground whose loss is decisive rather than merely expensive. Marking too much of an estate defeats the purpose: this archetype marks 75% of its elements, and an overlay that marks most of itself has not made a choice.
Which Terrain Layers Matter Most, and Why
The order and the shares are derived: each element’s weight is its criticality times its exposure, summed by layer and read against the estate’s total of 188. The explanations are written for the 3 layers that carry the shape.
The urban terrain. Tenant Portals, Service APIs, Shared Platform.
The heaviest single layer across all ten archetypes. Tenant portals, service interfaces and the shared platform itself are one failure domain by design, and the design is the mission — separating them would be building ten platforms rather than one.
The high ground. Federated Trusts, Platform Admins.
More identity weight than any other estate in the set, and the only one carrying two key-terrain elements on this layer: the per-tenant trust fabric and the platform administrators. Break-glass accounts are held offline and rebuilt before any tenant restore begins, which is what a two-hour recovery objective on a trust fabric actually requires.
The enablers of movement. Recovery Vault, Platform SOC, SOAR.
The lines of communication. Infrastructure Suppliers.
Terrain that is also the force. Platform Engineers.
The objective. Tenant Data.
Tenant data is segregated ground, and the estate makes segregation operational in recovery as well as in access: per-tenant vaults on independent credentials, so that restoring one tenant cannot reach another. That is the difference between segregation as a design claim and as a tested property.
The physical boundary. Regional Data Centers.
The federal-obligations profile — 3 declared, 3 out of scope
An obligation this estate does not incur is scored out of scope, not counted against it. That is the framework’s profile mechanism, and it is what stops an agency being marked down for failing to defend ground it does not hold.
Why this profile. Privacy terrain, tenancy and inheritance, and a statutory availability floor. Tenancy is the obligation that defines this shape, and it runs in the direction agencies find least intuitive: the provider is the one who must state what each tenant inherits, because the tenant cannot see it. Every tenant’s own FO-3 assessment resolves against the split published here, which makes this archetype’s profile the load-bearing half of nine other agencies’ obligations.
To make privacy exposure positional, so that the elements holding personal information can be defended, minimized and accounted for as terrain.
Carried byTenant Data (T5)
To make CUI movement declarable and therefore detectable, so that handling obligations attach to information rather than to systems.
Not assessedNo element of this estate carries it, so it is not a finding, not a gap and not deferred work.
To ensure that the customer half of a shared responsibility model is owned by someone, so that inherited controls do not become nobody's job.
Carried byShared Platform (T4), Tenant Data (T5)
To stop operational technology being scored as though it were a server estate, and to make the connections between the two declarable.
Not assessedNo element of this estate carries it, so it is not a finding, not a gap and not deferred work.
To identify the point at which a defensive action becomes a legal one, so that degradation decisions are bounded before they are needed.
Carried byShared Platform (T4)
To discharge the statutory supply chain risk obligation, and to make the boundary of its scope explicit rather than assumed.
Not assessedNo element of this estate carries it, so it is not a finding, not a gap and not deferred work.
The declaration is checked against the ground rather than trusted: every in-scope obligation above is carried by at least one element, and no element carries an obligation the profile omits. Adopting this shape means reviewing that declaration against your own estate — the profile that quietly omits an obligation you do incur is the one failure this mechanism can produce.
Its Typical Campaign Phase
Visible hardening, a deception grid, and a stated attribution posture.
Typical, not permanent. A phase is declared against a scope and can be declared backwards without embarrassment; this is where a well-run estate of this shape sits when it is not in contact. The full entry and exit conditions are on the Deter phase page.
Which maneuvers matter most — 11 of eleven forms evidenced
Ranked by the weight of the ground evidencing each form, not by how many elements name it. The 3 explained below are the ones that decide how this shape is defended; the rest are present and secondary. A form this estate does not evidence at all is not necessarily wrong for it — it is ground the archetype does not yet stand on.
Ensure no single failure is decisive.
The heaviest maneuver weight in any of the ten estates, and necessarily so. On shared infrastructure a single decisive failure is a failure for every tenant simultaneously, so no control is permitted to be the only one.
Give ground deliberately to preserve the force. Degrade gracefully; never fail open.
Isolation is the form that defines the archetype. The measurable question a tenant will ask is whether a compromise reaching one tenancy stops there, and answering it requires isolation planned in advance rather than improvised during an incident.
Force the adversary onto ground you own and watch.
Canalization is what makes multi-tenancy safe at all. Every path between tenancies that is not needed and not drawn is a path a compromise would otherwise be free to take.
Make identity, not network location, the decisive plane — surround the adversary with policy.
Restore the mission on evidence, not on hope — and prove it before you need it.
Buy decision time and prevent the adversary culminating on the objective.
Trade space for information and time, and impose cost.
Gain early warning and buy reaction time before the adversary touches key terrain.
Seize the initiative and evict before the adversary reaches the objective.
Convert contact into durable advantage rather than closing the ticket.
Disrupt adversary staging before the attack is launched.
Paths This Estate Declares Closed
A denial drawn on the overlay is a claim that can be tested. Stating that no path exists, as a path, is what turns an assumption into something an assessor can go and check — and what makes an observed connection a finding rather than a discovery.
Platform Adminshas no path toRecovery VaultDrawn as: no platform-admin path
Recovery Objectives This Shape Declares
Declared at the archetype level because they follow from the mission rather than from the technology. Where a deadline is set outside the agency, the recovery objective is constrained by it rather than negotiated against it.
| Element | Recovery time objective | Recovery point objective | How it is rebuilt |
|---|---|---|---|
| Federated TrustsT1 · per-tenant IdP | 2h | Zero — no acceptable loss | Trust fabric re-established from offline metadata; every tenant re-consents on rebuild |
| Shared PlatformT4 · multi-tenant | 4h | 15m | Platform rebuilt from declared infrastructure code; tenant inheritance re-asserted on rebuild |
| Platform AdminsT1 · privileged | 2h | Zero — no acceptable loss | Break-glass accounts held offline; rebuilt before any tenant restore begins |
| Tenant DataT5 · segregated | 4h | 15m | Per-tenant restore from the isolated vault; tenants restore independently of each other |
| Recovery VaultTX · isolated · offline | 4h | 15m | Per-tenant vaults on independent credentials; one tenant restore cannot reach another |
| Regional Data CentersT8 · facility · multi-tenant | 4h | Not declared | Not declared at archetype level. |
Federated Trusts
T1 · per-tenant IdP
- Recovery time objective
- 2h
- Recovery point objective
- Zero — no acceptable loss
- How it is rebuilt
- Trust fabric re-established from offline metadata; every tenant re-consents on rebuild
Shared Platform
T4 · multi-tenant
- Recovery time objective
- 4h
- Recovery point objective
- 15m
- How it is rebuilt
- Platform rebuilt from declared infrastructure code; tenant inheritance re-asserted on rebuild
Platform Admins
T1 · privileged
- Recovery time objective
- 2h
- Recovery point objective
- Zero — no acceptable loss
- How it is rebuilt
- Break-glass accounts held offline; rebuilt before any tenant restore begins
Tenant Data
T5 · segregated
- Recovery time objective
- 4h
- Recovery point objective
- 15m
- How it is rebuilt
- Per-tenant restore from the isolated vault; tenants restore independently of each other
Recovery Vault
TX · isolated · offline
- Recovery time objective
- 4h
- Recovery point objective
- 15m
- How it is rebuilt
- Per-tenant vaults on independent credentials; one tenant restore cannot reach another
Regional Data Centers
T8 · facility · multi-tenant
- Recovery time objective
- 4h
- Recovery point objective
- Not declared
- How it is rebuilt
- Not declared at archetype level.
The Estate as the Overlay Lays It Out
The tier bands the archetype ships with, top to bottom, with every element in each. 12 elements and 14 drawn paths in total.
Tenant Interface4 elements · 2 decisive
Shared Platform3 elements · 2 decisive
The Failure Modes Characteristic of This Shape
Not general bad practice. These are the ways a competent program built on this particular shape goes wrong while continuing to report that it is fine.
Tenant-facing assurance is a certificate rather than a boundary.
- The tell
- Tenants receive an authorization package and cannot state which controls they inherit for their own workloads.
- The correction
- Publish the inheritance split per service, in the form a tenant’s own FO-3 assessment can consume. An inheritance statement a tenant cannot act on is a document, not a control.
Recovery is planned for the platform rather than for tenants.
- The tell
- The restore plan brings the platform back as a unit, and no tenant can be restored independently of the others.
- The correction
- Exercise a single-tenant restore. Per-tenant vaults on independent credentials are the design; whether one tenant’s restore can reach another’s data is the test.