
Operations
Part of Running productivity software as a dependable service with an operating charter
Six ownership functions for running productivity software without gaps
Six evidence-backed ownership functions for running productivity software, with clear boundaries for accountability, workflow, access, quality and response.
These six business productivity software team roles are ownership functions, not a proposed organisation chart. A small company may combine several; a larger one may split each across specialists. What matters is that every material decision has a named person and a deputy.
The non-ranked list was researched on 5 September 2026 for organisations in England. Inclusion required a distinct operating responsibility and a current authoritative UK record that explains it. We excluded vendor-created job titles, salary claims and headcount ratios.
What to take away
- Public-sector role descriptions are reference models, not private-sector obligations.
- Separating proposal, release and acceptance of material control changes avoids conflicts.
- The list is complete only when it matches the organisation's risks and operating model.
1. Accountable service owner
This person approves scope, priorities, material risk and service-level trade-offs. They resolve conflict between teams and remain answerable for the end-to-end outcome, even when administration is delegated.
The Government Digital and Data capability framework says a service owner is accountable for quality, performance, benefits and outcomes. Use that record to define accountability, not to copy a civil-service grade or structure into a business. The appointment needs sufficient authority, time and access to evidence.
The artefact is a decision log that records approved scope, priority and risk trade-offs, with the date and the person who approved each one.
2. Workflow custodian
The custodian owns intake rules, states, templates, handovers and exception routes. They examine whether the configured process still matches real work, and they maintain a controlled backlog of proposed changes.
GOV.UK's description of service-team roles assigns product and delivery responsibilities within multidisciplinary work. In a private organisation, the equivalent function may sit with operations, a product manager or a process lead. The title is secondary to the decision right: someone must accept or reject workflow alterations and record when definitions change.
The artefact is a change backlog listing each proposed alteration to workflow, its status and the date the decision was recorded.
3. Platform administrator
The administrator manages configuration, identities, groups, permissions and supported integrations within an approved design. They retain auditable records of elevated access and know how to contact the supplier.
NCSC guidance for secure use of SaaS covers authentication, privileged administration, data, monitoring and incident preparation. Those activities justify a named administrative function. They do not make that person the sole security authority or the owner of every business decision.
The artefact is an access log of privileged accounts and elevated permissions, reviewed on a fixed cycle and retained for audit.
4. Quality and acceptance owner
This function turns "looks fine" into reproducible checks. It maintains representative journeys, verifies fixes and records defects, evidence and accepted limitations. Independence should increase with the consequence of failure.
Government quality-assurance guidance places testing across a multidisciplinary team and covers normal and unusual conditions. Although written for government services, it supports an important boundary: the person who built a workflow should not be the only person deciding that a high-risk change is acceptable.
The artefact is a defect register that records each defect, the supporting evidence, the severity and any accepted limitation.
5. Support and incident lead
The lead owns the support route, triage, escalation, communication and learning after disruption. They coordinate technical, supplier, management, privacy and communications input rather than trying to perform every specialism.
The NCSC's incident-management guidance connects response with recovery, continuity, roles and maintained plans. Security incidents are only part of the workload; the same operational clarity also helps with outages and serious data-quality failures. Suspected personal-data breaches must reach the organisation's qualified privacy team promptly.
The artefact is an incident log that records triage decisions and the lessons agreed after each disruption.
6. Performance and feedback owner
This person defines measures, checks data quality and brings operational numbers together with user evidence. They challenge attractive figures that do not answer the service question and preserve definitions when dashboards change.
GOV.UK guidance on setting performance metrics starts from service purpose, hypotheses, data sources and context. Central-government reporting duties do not transfer to private firms, but the method supports a distinct measurement function rather than leaving interpretation to whoever built the report.
The artefact is a metric definitions register that states each measure, its source and its known limitations.
Allocate functions on one page
For each function, name the accountable person, deputy, decisions, routine tasks, evidence location and escalation route. Then look for gaps and conflicts. Combining workflow and platform administration may be practical; allowing the same person to propose, release and accept a material control change may not be.
For a small firm, combining is normal. For a larger one, splitting each function across specialists is normal. The table is illustrative, and the split should follow risk rather than headcount alone.
20-person firm, typical combination
- Accountable service owner
- Managing director
- Workflow custodian
- Operations manager
- Platform administrator
- IT lead, often shared with a managed service
- Quality and acceptance owner
- Operations manager, with a peer checking high-risk changes
- Support and incident lead
- Office or IT manager
- Performance and feedback owner
- Finance or operations manager
200-person firm, typical split
- Accountable service owner
- Operations director
- Workflow custodian
- Product manager for internal tools
- Platform administrator
- Platform administrator
- Quality and acceptance owner
- Quality lead and a tester
- Support and incident lead
- Service desk lead
- Performance and feedback owner
- Performance analyst
At 20 people, one manager can hold two or three functions. At 200, each function can sit with a different named person. Which pairs may combine depends on the risk in the change, not on the size of the firm.
Employment, regulated-sector and contractual duties can require other roles. Have qualified advisers review the arrangement. The list is complete only when it matches the risks and actual operating model of the organisation using it.
Before you act
- Confirm each of the six artefacts exists, is current and has a named owner.
- Walk one exception route end to end before you rely on it.
- Repeat the review of the split when headcount, suppliers or risks change.
Common questions
How should a business use the Government Digital and Data service owner record?
Use that record to define accountability, not to copy a civil-service grade or structure into a business. The appointment needs sufficient authority, time and access to evidence, and the person remains answerable for the end-to-end outcome even when administration is delegated.
Why should the person who built a workflow not accept a high-risk change alone?
Government quality-assurance guidance places testing across a multidisciplinary team and covers normal and unusual conditions. It supports an important boundary: the person who built a workflow should not be the only person deciding that a high-risk change is acceptable.



