6MM & Partner Responsibility Matrix

Clarify ownership for trading infrastructure, integration security, end-user operations, monitoring, support, incidents, and compliance.

View as Markdown

A clear responsibility model reduces operational risk and helps support teams respond faster.

Responsibility split

Area6MMPartner
Trading infrastructureMatching, risk, trading engine, API and SDK capabilitiesCorrect integration and production monitoring
End-user relationshipNo direct customer relationship unless separately agreedUser onboarding, support, disclosures, and account lifecycle
Secrets and credentialsProvides credential model and signing requirementsStores secrets securely and restricts internal access
WebhooksSends signed lifecycle eventsVerifies signatures and processes events idempotently
Compliance operationsProvides compliance-oriented technology and support materialsConfirms local obligations and user-facing requirements
Integration releasesMaintains documented platform and integration capabilitiesTests partner code, configuration, and user journeys before release
Incident handlingInvestigates relevant 6MM infrastructure and provides partner support channelsDetects user-facing impact, preserves evidence, contains partner systems, and escalates

Responsibilities by lifecycle

StagePartner action
DesignDefine user ownership, asset flow, data flow, support model, and target jurisdictions.
BuildKeep secrets on the backend, implement supported authentication, and preserve business identifiers.
TestExercise timeout, retry, duplicate-webhook, expired-token, and failure scenarios.
LaunchComplete readiness review, establish monitoring, and document support escalation.
OperateReview alerts, reconcile abnormal operations, rotate credentials, and maintain audit evidence.
IncidentContain partner-controlled systems, protect credentials, preserve UTC timelines, and contact the correct 6MM channel.

Operational handoff checklist

  • Name the owner for integration health, security, compliance, and end-user support.
  • Document production base URLs, credential owners, and rotation procedures.
  • Confirm dashboards and alerts for authentication, order, transfer, and webhook failures.
  • Store request IDs, partner order numbers, and event IDs in searchable logs.
  • Define which events require immediate escalation.
  • Keep the Support Request Template available to the operations team.