> ## Documentation Index
> Fetch the complete documentation index at: https://docs.galtea.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Responsibility matrix

> Who does what in each of the five models.

Who does what, per model. **G** = Galtea, **C** = Customer, **G+C** = shared, with the split
described in the notes.

## Models 1 to 3: Galtea operates the infrastructure

| Responsibility | 1. Shared SaaS | 2. Enterprise org | 3. Private tenant |
| - | - | - | - |
| **Infrastructure** | | | |
| Provision cloud account | G | G | G |
| Provision and patch Kubernetes cluster | G | G | G |
| Provision database | G | G | G |
| Provision object storage | G | G | G |
| Network design and firewall rules | G | G | G+C |
| DNS and TLS certificates | G | G | G |
| **Platform** | | | |
| Install the platform | G | G | G |
| Apply upgrades | G | G | G |
| Ship fixes and new versions | G | G | G |
| Capacity sizing and scaling | G | G | G |
| Configure LLM providers and models | G | G | G+C |
| **Identity** | | | |
| Operate the identity provider | G | G | G |
| Register Galtea in your IdP | n/a | C | C |
| Map groups to roles | n/a | G+C | G+C |
| Manage users and roles in the product | C | C | C |
| Manage and revoke API keys | C | C | C |
| **Data** | | | |
| Database backups and restore testing | G | G | G |
| Data retention configuration | G | G | G+C |
| Deciding what test data is uploaded | C | C | C |
| **Security** | | | |
| Platform vulnerability patching | G | G | G |
| Cluster and OS patching | G | G | G |
| Web application firewall | G | G | G |
| Egress allowlist definition | G | G | G+C |
| Credentials for your product endpoints | C provides, G stores | C provides, G stores | C provides, G stores |
| Penetration testing coordination | G+C | G+C | G+C |
| **Operations** | | | |
| Monitoring and alerting | G | G | G |
| First-line incident response | G | G | G |
| Root-cause analysis of product bugs | G | G | G |
| Status communication | G | G | G |

## Models 4 and 5: you operate the infrastructure

| Responsibility | 4. In your cluster | 5. Self-hosted |
| - | - | - |
| **Infrastructure** | | |
| Provision cloud account | C | C |
| Provision and patch Kubernetes cluster | C | C |
| Provision database | C | C |
| Provision object storage | C | C |
| Network design and firewall rules | C | C |
| DNS and TLS certificates | C | C |
| **Platform** | | |
| Install the platform | G | C |
| Apply upgrades | G | C |
| Ship fixes and new versions | G | G |
| Capacity sizing and scaling | G+C | C |
| Configure LLM providers and models | G+C | C |
| **Identity** | | |
| Operate the identity provider | C | C |
| Register Galtea in your IdP | C | C |
| Map groups to roles | C | C |
| Manage users and roles in the product | C | C |
| Manage and revoke API keys | C | C |
| **Data** | | |
| Database backups and restore testing | C | C |
| Data retention configuration | G+C | C |
| Deciding what test data is uploaded | C | C |
| **Security** | | |
| Platform vulnerability patching | G | G ships, C applies |
| Cluster and OS patching | C | C |
| Web application firewall | C | C |
| Egress allowlist definition | C | C |
| Credentials for your product endpoints | C provides, G stores | C |
| Penetration testing coordination | G+C | C |
| **Operations** | | |
| Monitoring and alerting | G+C | C |
| First-line incident response | G | C |
| Root-cause analysis of product bugs | G | G, with logs from C |
| Status communication | G | C internally |

## Notes on the shared items

**Network design in a private tenant.** Galtea designs and operates the tenant network.
You decide how your side reaches it (VPN client, site-to-site routing peer, private link,
or peering) and which of your IP ranges are allowed. Galtea implements what you decide.

**Group-to-role mapping in federated mode.** You own the groups in your directory. Galtea
owns which product permissions each role carries. The mapping between them is agreed once
and then driven entirely by your directory: a membership change on your side takes effect at
the user's next sign-in.

**LLM provider configuration in a private tenant.** Galtea configures the gateway. You
decide whether inference runs on Galtea's provider accounts or on yours, and whether the
model set is restricted to an approved subset.

**Egress allowlist in a private tenant.** You tell Galtea which of your endpoints the platform
must call. Galtea adds them to the allowlist. Nothing else is reachable.

**Product bugs in a self-hosted install.** Galtea fixes bugs and ships a version regardless
of model. In a self-hosted install Galtea cannot see your environment, so reproducing the
bug depends on the logs and version information you provide, and applying the fix depends on
you upgrading.

## The one-sentence version

In models 1 and 2 you manage users and test data, and nothing else. In model 3 you
additionally decide the network and identity boundary while Galtea still operates
everything. In model 4 you operate a platform that Galtea builds and supports.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.