Paste the cloud services you use. See which controls are yours, the provider's, or shared.
Swipe sideways for all 14 areas.
| Service | GOV | IAM | DAT | KEY | NET | LOG | VUL | CFG | APP | INC | BCP | PHY | SUP | AIR |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| S1 Virtual machines for the claims API | shared | yours | yours | yours | yours | yours | yours | yours | yours | shared | yours | the provider's | shared | yours |
| S2 Virtual machines for batch reporting | shared | no owner | no owner | no owner | no owner | no owner | no owner | no owner | no owner | shared | no owner | the provider's | shared | no owner |
| S7 Object storage buckets holding customer files | shared | yours | yours | yours | shared | yours | yours | yours | yours | shared | yours | the provider's | shared | yours |
| S10 Managed relational database | shared | yours | yours | shared | shared | shared | shared | shared | yours | shared | shared | the provider's | shared | yours |
| S16 Hosted LLM API for the support chatbot | shared | yours | yours | shared | shared | shared | the provider's | shared | shared | shared | shared | the provider's | shared | yours |
| S19 Identity provider (SSO) | shared | yours | yours | the provider's | the provider's | shared | the provider's | shared | the provider's | shared | shared | the provider's | shared | shared |
| S22 Managed firewall | shared | no owner | no owner | shared | run by the MSP | shared | shared | shared | no owner | shared | shared | the provider's | shared | no owner |
| S30 CRM | shared | shared | yours | the provider's | the provider's | shared | the provider's | shared | the provider's | shared | shared | the provider's | shared | shared |
36 services, 38 controls nobody owns.
504 bays: 159 yours, 67 the provider's, 246 shared, 4 run by the MSP, 28 not drawn.
Cloud Shared Responsibility Mapper reads your list of cloud services and maps the shared responsibility model onto it, service by service and control area by control area. Paste the cloud services you use. Get a shared responsibility map per service and control area, what the provider owns, what you own and what is shared, with the Cloud Controls Matrix, ISO/IEC 27017 and 27018 clauses behind each split, and the customer-owned controls nobody has named.
Paste service names and service models only: no account ids, no architecture, nothing from inside your cloud. The list is read in your browser and nothing is stored until you save.
Pick your frameworks and, for CMMC, your level: the split is shown for what you are assessed against.
The split follows the published shared responsibility model for each service model, with the clause behind it. Check it against your provider's own documentation before you hand it to an assessor.

Paste the service list you already keep
One service per line: the name alone, or with any of provider, service model, region, data classification, CMMC scope, SOC 2 scope, owner, MSP and notes. Each is placed on one of 48 published service categories; a line that matches none is marked unplaced and never guessed. Anything that looks like an account id, a resource name, an address, a hostname or a key is removed before it is read.
Read the responsibility plan
Every service a strip, every control area a bay: edged red where the shared responsibility model makes it yours, shaded where the provider retains it, hatched where it is shared. A bay that is yours with no owner on the line carries a red corner: the orphaned control an assessor finds first.
Hand over the customer responsibility matrix
Eleven findings in fixed order, each with the services it names, the clause quoted from the Cloud Controls Matrix, ISO/IEC 27017 and 27018, SOC 2, CMMC, C5 or ISO/IEC 27001, and the question to take to the platform owner. The matrix exports in the columns an assessor expects.
The Cloud Controls Matrix, ISO/IEC 27017 and the STAR shared responsibility disclosure are always shown: they are the cloud-specific codes that allocate each control.
Why a responsibility plan and not a consultant's workshop
Every provider publishes its side of the shared responsibility model, and every assessor asks for yours: a customer responsibility matrix that names who owns each control on each service. Most estates keep that as a spreadsheet of services with no column for control ownership, so the orphaned control, the one the model makes yours and nobody on your side runs, is found in the assessment. This draws the SSRM over the list you already have, in your browser, with the clause behind every split, and names every orphaned control before the assessor does.