The boundary, drawn per surface

SurfacePlatform ownsBrand owns
Lobby & contentThe lobby framework, section mechanics, placement toolingCuration, ordering choices, the audience-fit call
BonusingThe engine, cost ceilings, eligibility gates — one rule engineCampaign design, offers and creative inside the envelope
CRMRails, gates, suppression, the automation layerVoice, journeys, segment strategy
CashierProviders, orchestration, method availability per marketNothing player-money-mechanical; presentation within limits
Compliance surfaceEverything — mechanisms and values both, per the matrixObligation to operate inside it, without exception paths
DataThe warehouse, definitions, identityBrand-scoped analysis on shared definitions

The queue: where the boundary gets stress-tested

Every brand's growth plan eventually wants a mechanism the platform doesn't have, and the queue is where those wants meet finite capacity. The governance that holds: a published prioritisation rule (compliance first, then evidence-weighted revenue, then portfolio strategy), a queue every brand can see, a named tie-breaker for genuine conflicts, and — the underrated half — a fast lane that isn't one: self-service configuration so the small requests never enter the queue at all. Queue credibility is a stock that opacity spends and visibility rebuilds slowly.

Guardrails against the fork

The existential risk of the shared platform is not the queue's speed — it is the accumulation of per-brand exceptions that quietly turn one platform into several. Three defences: the mechanism-vs-configuration test applied at intake (disguised mechanism changes named as such), new mechanisms built once, multi-tenant, even when one brand funds them (the funder gets priority, not exclusivity — unless the portfolio deliberately decides otherwise), and a periodic fork audit: any behaviour that exists for exactly one brand gets justified or generalised. This is the configure-don't-fork argument turned inward, and it compounds identically.

Incidents across the seam

The joint runbook, agreed in peacetime: severity classes shared by both sides; the platform owns diagnosis, fix and the honest timeline; the brand owns player communication and goodwill; compliance owns every regulator contact. The postmortem's output lands as platform improvements and runbook edits — never as a brand-side workaround, because workarounds are forks with an incident as their origin story.

The relationship, reviewed

Quarterly, the same three questions as every seam in the org design: is the boundary being used, bypassed or renegotiated? Bypasses (shadow tools, side-deals, disguised requests) mark boundary errors; renegotiations are healthy when explicit. The platform-brand relationship is the multi-brand group's marriage — it does not need to be frictionless, it needs its arguments refereed by rules both sides helped write.

Continue reading: Scaling operations — how this seam industrialises with brand count. Shared services — the operating form of the platform side.