THIS EXPLANATION
THE ROOM
CDA·239 Computing, Data & AI 6 MIN · 8 STATIONS

Three kinds of responsible person

A Socratic walk-through of three kinds of responsible person — reasoned out one step at a time, not lectured.

abcdefgh
a

The question we started with

THE QUESTION #

Why does one dataset need someone who owns it, someone who tends it, and someone who merely holds it?

A governance programme announces that every dataset must have an owner, a steward, and a custodian. The room's first reaction is nearly always the same: three names for one job, invented by people who like org charts.

It is a fair suspicion, and it deserves a fair test. Suppose we did appoint one person and called them Responsible For The Customer Table. What would we be asking them to do — and could any one person actually do it?

b

Reasoning it through

REASONING #

Let us list the questions that genuinely arise about a real dataset over a year.

May the marketing team use this for a new campaign? Does "active customer" include someone who cancelled last week? Why did the row count drop eleven percent on Tuesday? Is it encrypted at rest? Who approved that analyst's access? We are retiring the source system — what happens to the history?

Now look at what each question needs from whoever answers it. The campaign question needs authority: someone whose decision binds, who can be answerable if it turns out to have been the wrong call. The definition question needs subject knowledge: what the business means by active, which cases are edge cases, why the definition changed in March. The row-count and encryption questions need operational control of the system: access to the pipeline, the backups, the key management.

Notice these are three different scarcities. Authority is scarce because it must sit with someone accountable for the outcome — typically a senior businessperson. Meaning is scarce because it lives in whoever works with the data daily. Technical control is scarce because it requires production credentials and platform skill. Almost nobody has all three, and the few who do become a bottleneck the moment there are more than a handful of datasets.

So the split is not bureaucratic tidiness. It is a response to the fact that the decision rights, the domain knowledge, and the operational keys naturally live in different people — and forcing them together either gives a business leader production credentials, or gives an engineer the authority to decide what customer data may be used for. Both are the arrangements that go wrong.

Which lets us name the roles properly:

The owner is accountable. They decide who may use the data and for what, they accept the risk, they sign off on definitions and on disposal. They are usually not technical and rarely touch the data.

The steward curates the meaning. They maintain definitions and business rules, resolve ambiguity, monitor quality, decide when a value is wrong, and act as translator between what the business means and what the tables contain. They advise the owner; they do not decide for them.

The custodian safeguards and operates. Storage, backup, encryption, availability, implementing the access the owner granted. Critically, the custodian holds the data without holding any authority over its use — and that separation is the entire point of the role.

One honest note: the words are not standardised. Some frameworks fold stewardship into ownership; some call the custodian a data trustee or the technical owner; the DAMA body of knowledge and most in-house policies differ in vocabulary. What is stable across all of them is the three functions — accountability, curation, safekeeping — not the three job titles.

c

The analogy

THE ANALOGY #
THE FIGURE

Think of a painting on loan to a museum. The collector owns it: they decide whether it may be exhibited, lent onward, photographed for a catalogue, or sold. The curator knows it: its provenance, what it depicts, which attribution is disputed, how it relates to the rest of the room. The conservator holds it: the climate control, the mounting, the insurance, the alarm. Three people, one object, and none of them can do another's job. The conservator who decided the painting should tour would be exceeding their role even if they were right; the collector who tried to reline the canvas himself would be a disaster.

WHERE IT BREAKS DOWN

a painting can be in only one place, so responsibility for it is naturally exclusive — whereas a dataset is copied, joined, and derived endlessly, so the harder governance question is not who is responsible for the copy but whether the ownership travels with the copy, which the museum has no equivalent of at all.

d

Clarifying the model

THE MODEL #

Three refinements.

First, the misconception that these are three levels of seniority — owner above steward above custodian. They are not a hierarchy; they are different kinds of responsibility over the same object. The steward will often know far more about the data than the owner does, and correctly so. What the owner has is not superior knowledge but the authority to decide, and the answerability that goes with it.

Second, the roles must attach to a thing, not float. "Owner of data" is meaningless; "owner of the customer master, including its definitions and its access decisions" is testable. If nobody can say precisely which datasets a name covers, the role has not actually been assigned.

Third, the failure mode this arrangement is designed against. When the three collapse into one, you get either an accountable person who cannot see what is happening to the data, or a technically capable person quietly making policy decisions they were never given authority for. That second one is common and almost invisible: an engineer grants access because a request seemed reasonable, and a decision that should have been the owner's has been made by the person holding the keys.

e

A picture of it

THE PICTURE #
Three kinds of responsible person
Three kinds of responsible person Read the three role branches as answers to three different questions about the same dataset -- who may decide, who knows what it means, who keeps it safe -- rather than as three ranks. The fourth branch is what you get when two of them land on one person: each item there is a real failure, and each names which pair was merged. {"generator":"mermaid-svg-renderer@3.2.1","source":"../Socrates/.diagram-cache/_src/three-kinds-of-responsible-person.md","sourceIndex":1,"sourceLine":4,"sourceHash":"5a8e3f7c7dc4dd7d0ac762109140804f75ab7e4300436ff998500e4d959a3233","diagramType":"mindmap","layoutVariant":"source","repairedDuplicateIds":[{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_1","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_1--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_2","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_2--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_3","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_3--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_4","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_4--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_5","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_5--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_6","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_6--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_7","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_7--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_8","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_8--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_9","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_9--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_10","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_10--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_11","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_11--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_12","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_12--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_13","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_13--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_14","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_14--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_15","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_15--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_16","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_16--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_17","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_17--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_18","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_18--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-node_19","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-node_19--duplicate-2"},{"original":"mermaid-5a8e3f7c7dc4dd7d-0-gradient","replacement":"mermaid-5a8e3f7c7dc4dd7d-0-gradient--duplicate-2"}],"motion":"entrance-with-reduced-motion-fallback","presentation":"editorial","attempt":1,"viewBox":{"x":0,"y":0,"width":1179,"height":536},"qa":{"passed":true,"findings":[]}} One dataset, threeresponsibilities Owner accountable Decides permitted uses Approves who getsaccess Accepts the risk Signs off on disposal Steward curates meaning Maintains definitions Resolves ambiguouscases Monitors quality Translates business toschema Custodian safeguards Storage and backup Encryption and keys Availability and recovery Implements grantedaccess When they collapse Keys without authority Authority without visibility Definitions owned bynobody

How to readRead the three role branches as answers to three different questions about the same dataset — who may decide, who knows what it means, who keeps it safe — rather than as three ranks. The fourth branch is what you get when two of them land on one person: each item there is a real failure, and each names which pair was merged.

f

What became clearer

WHAT CLEARED #
WHAT CLEARED

The three roles exist because responsibility for data is not one thing. Deciding, defining, and safeguarding require different authority, different knowledge, and different access, and the split is what stops the person holding the keys from quietly becoming the person setting the policy.

g

Where to go next

ONWARD #
  • How ownership should behave when a dataset is copied or derived into a new product.
  • Domain-oriented ownership as an alternative to a central governance office.
  • Why access approval is the specific decision most often delegated by accident.
h

Key terms

TERMS #
TermWhat it means
Data ownerthe accountable party who decides permitted uses and access, and bears the consequences of those decisions.
Data stewardthe curator of a dataset's meaning: definitions, business rules, quality, and edge cases.
Data custodianthe technical holder responsible for storage, protection, availability, and implementing access decisions.
Accountabilityanswerability for an outcome, which unlike a task cannot be shared or delegated away.
Segregation of dutiesdeliberately separating the authority to decide from the ability to execute, so neither alone can act unchecked.

Every term the collection defines is gathered in the glossary.

Nearby on the shelf

4