Shared Responsibility Model
a governance framework, adapted from cloud computing, dividing security and governance obligations between a vendor (what they control and secure) and a customer (what remains theirs to configure and govern) in a third-party service relationship.
Defined in 2 GAGE programs, which carry 2 distinct definitions of it. The wording above is taught in Certified Agentic AI Governance Professional (CAAGP).
How each discipline defines it
The same term does different work depending on who is using it. These are the definitions as each program teaches them, unedited.
The division of security and configuration responsibility between a cloud provider (typically responsible for the underlying infrastructure) and the customer organization (typically responsible for access, encryption, and retention configured on top of it), relevant to this topic because it splits the custodian role across an internal and an external party.
a governance framework, adapted from cloud computing, dividing security and governance obligations between a vendor (what they control and secure) and a customer (what remains theirs to configure and govern) in a third-party service relationship.
Where it is taught
The exact lessons this term appears in. The first module of every program is free with a free account.
- Testing What You Did Not Build · Testing and Red-Teaming, Certified Agentic AI Governance Professional (CAAGP)
- Stewardship that survives reorgs: roles attached to data, not to people who leave · The Catalog That Lives, Certified AI Data Governance Professional (CADGP)
Terms it appears with
Not an alphabetical neighbourhood: these are the terms taught in the same lessons, ranked by how often they appear together.