Run it yourself, or join a shared service?
Either way the mission needs a mission-side team. Joining a shared offering does not remove the team; it changes what the team does. The people who understand today's mission help define how tomorrow's environment will work.
Two operating models, one skill set.
Illustrated for a network specialist who knows local connectivity, application paths, DNS, routing, and troubleshooting. The mission knowledge carries forward; the tools and handoffs change. A mission can combine the models component by component.
| The skill | Mission manages its own cloud foundation | Mission consumes enterprise shared services |
|---|---|---|
| Know what connects to what | Maintain the dependency map and translate flows into the mission-managed virtual network design. | Maintain the mission dependency map and submit connection, DNS, and routing requirements to the service owner. |
| Manage network changes | Implement approved routes, segmentation, and policies within delegated access and the mission's change process. | Prepare the request and test plan. The enterprise provider implements inside its boundary; the specialist validates the mission path. |
| Troubleshoot service paths | Use approved logs and tools to isolate and fix faults in mission-owned components; escalate carrier or provider issues. | Isolate whether the fault is local, application, identity, or shared-service; provide traceable evidence; work the enterprise service desk. |
| Document the environment | Keep diagrams, configuration evidence, and boundary changes current with the security and system owners. | Keep mission-side flows current; request provider evidence; track inherited-service changes. |
| Support local users | Coordinate retained site, campus, WAN, and cloud connectivity with their owners. | Coordinate the retained local path and the enterprise cloud path. Moving hosting does not move every local connection. |
Army ECMA and cARMY
Public sources only. Illustrative, not an ECMA service catalog or an agreed assignment of responsibilities.
The Enterprise Cloud Management Agency centrally manages Army cloud policy and the cARMY environment. Intake runs through the Cloud Modernization Approval Process. Thirty-one Common Shared Services are published, with detail behind CAC; IL2, IL4, IL5, and IL6 are available in AWS and Azure. The mission owner still retains data ownership, application operations and maintenance, and application-layer RMF, and a per-application RACI is contractually required. The responsibility split is engineered per tenant, never assumed.
Make the handoffs visible.
R does the work · A is accountable for the result · C is consulted · I is informed. One accountable owner per activity. Multiple R entries need an agreed task split. Illustrative responsibilities, confirmed in the workshop.
| Activity | Enterprise shared-service owner | Mission owner | Cloud Foundations team | Mission network specialist | Mission application operator |
|---|---|---|---|---|---|
| Operate the shared platform service | A/R | I | C | C | I |
| Approve mission access and data requirements | C | A | R | C | C |
| Map mission network dependencies and data flows | C | A | C | R | C |
| Integrate a mission workload with shared services | C | A | R | R | R |
| Implement an approved change inside the enterprise network service | A/R | I | C | C | I |
| Patch and support the mission application | I | A | C | C | R |
| Coordinate a mission incident across providers | C | A | R | R | R |
| Validate mission recovery after a disruption | C | A | R | R | R |
For a platform incident the enterprise service owner stays accountable for its own restoration. For authorization the government Authorizing Official keeps the decision. Expand the sample with security, acquisition, and other owners as needed.