Part 7 · 2 chapters · ~20 min

The Organisation

Platform, country and concern teams with what each owns and is measured by, the extension-point request as the organisational interface, the failure modes and written decision rights, and on-call across time zones: tenant-routed alerts, follow-the-sun with written handovers, levers by tenant, regulator clocks per country, and the three rituals that replace memos.

15

Platform teams and country teams

the organisation mirrors the repo
  1. The platform team owns the core, the extension-point interfaces and contract suites, the config schema and rules engine, the train, the launch checklist and the migration machinery; ten to thirty engineers for a dozen countries; measured by launch time trending down, core changes per launch toward zero, and country teams' velocity. Its product is the country teams' speed.
  2. A country team owns its package, adapters (jointly with the concern sub-team), rules with its compliance lead, catalogues with its native reviewer, its launch, its market's on-call and support escalation; five to fifteen people including compliance and support; measured by the market's metrics and its launch and incident numbers.
  3. Concern sub-teams (identity, payments, compliance tooling) own an interface and its contract suite, consult on every country's adapter for that concern, and are second owners in CODEOWNERS. They are how one person who understands KYC across twelve countries exists.
  4. The interface between teams is the extension-point request: the need, the second country that shares it (the rule of two, part 5), a general design by the platform and sub-team, the first adapter by the requesting country; no second country gets a slot or a flag. The queue's latency is a metric: a slow queue is where forks begin.
  5. Failure modes: speculative points; a core patch for a deadline (the lint from part 4 and the review from the Big-company FE course part 7 are mechanical because the pressure is constant); an unowned concern; a platform team that becomes a ticket queue.
  6. Decision rights, written: the platform decides the core and interfaces with countries consulted; a country decides its config, rules and adapters within the interfaces with the sub-team consulted; compliance in each country vetoes rules and disclosures; the train is the platform's and the hotfix lane is the only exception. Written, because the week before a launch tests every one.
PLATFORM TEAMS AND COUNTRY TEAMS
who owns the core, who owns the adapters, and the interface between them
swipe the figure sideways, or tap expand for full screen
1/6
the platform team
The platform team: owns packages/core, the extension-point interfaces and contract suites, the config schema and the rules engine, the release train, the launch checklist and the migration machinery; measured by launch time trending down, the count of core changes per launch (toward zero), and the country teams' velocity. Ten to thirty engineers for a dozen countries; the Big-company FE course part 0's platform group, for a platform of countries.
16

On-call across time zones, and the rituals

the market's daytime is someone's night
  1. Who is paged: a market alert (cut by tenant: the Big-company FE course part 8) pages the country team's on-call in that market's hours and language; a core alert (every tenant at once, a ring breach, the config service down) pages the platform on-call wherever the sun is. The tenant dimension routes it.
  2. Follow-the-sun: the platform on-call rotates across three regions, eight hours each, with a written handover at each boundary (open incidents and state, active rings and numbers, switches flipped, the hotfix in the lane, the thing to watch). A verbal handover is a lost incident. Country teams cover their own hours and escalate by the region map.
  3. Levers by tenant: a kill switch, a config rollback and a rule-set rollback per country; one tenant's ring halted without the others; the global levers (previous artefact, forced reload: the Architecture course part 7) that need the platform on-call. The runbook names which are which per failure class.
  4. Communication: a status page per country in its language driven by its tenant's alerts; an incident channel named by tenant; support per market reading it; a regulator notification clock per country owned by its compliance lead (a data incident reported within N hours). The platform on-call does not speak to twelve regulators; the country teams do, with the platform's facts.
  5. The rituals: a weekly platform-and-country sync (the request queue, the launch calendar, migrations, incident summaries); a monthly launch review (each launch and ring against its checklist, and what the checklist gained); a quarterly extension-point review (every point, its adapters, its last change: one-adapter points after a year fold back into config, unused points are deleted).
  6. What replaces memos: the request queue, the checklist, the dashboards, the decision rights, the three rituals. A platform of countries on memos and chat forks by the third country; on these artefacts it launches the twelfth in a quarter. The organisation is the last extension point, and the one most often left undesigned.
the exercise, for the course
For your product, write the five artefacts: who decides what, the extension-point request process, the launch checklist's first ten lines, the on-call map by tenant, and the three rituals' agendas. Where you cannot write one, that is where your platform is still a product with a long country list.
ON-CALL ACROSS TIME ZONES, AND THE MEETINGS THAT REPLACE MEMOS
who is paged for a market at 3 am, the follow-the-sun handover, and the three rituals a platform of countries needs
swipe the figure sideways, or tap expand for full screen
1/6
who is paged
Who is paged: a market alert (the Big-company FE course part 8's alerts, cut by tenant: a flow success drop in Nigeria, a new error signature in Kenya) pages the country team's on-call in that market's hours; a core alert (a flow success drop in every tenant at once; a train ring breach; a config service failure) pages the platform on-call wherever the sun is. The alert's tenant dimension is what routes it.