The boundary, drawn per surface
| Surface | Platform owns | Brand owns |
|---|---|---|
| Lobby & content | The lobby framework, section mechanics, placement tooling | Curation, ordering choices, the audience-fit call |
| Bonusing | The engine, cost ceilings, eligibility gates — one rule engine | Campaign design, offers and creative inside the envelope |
| CRM | Rails, gates, suppression, the automation layer | Voice, journeys, segment strategy |
| Cashier | Providers, orchestration, method availability per market | Nothing player-money-mechanical; presentation within limits |
| Compliance surface | Everything — mechanisms and values both, per the matrix | Obligation to operate inside it, without exception paths |
| Data | The warehouse, definitions, identity | Brand-scoped analysis on shared definitions |
The queue: where the boundary gets stress-tested
Every brand's growth plan eventually wants a mechanism the platform doesn't have, and the queue is where those wants meet finite capacity. The governance that holds: a published prioritisation rule (compliance first, then evidence-weighted revenue, then portfolio strategy), a queue every brand can see, a named tie-breaker for genuine conflicts, and — the underrated half — a fast lane that isn't one: self-service configuration so the small requests never enter the queue at all. Queue credibility is a stock that opacity spends and visibility rebuilds slowly.
Guardrails against the fork
The existential risk of the shared platform is not the queue's speed — it is the accumulation of per-brand exceptions that quietly turn one platform into several. Three defences: the mechanism-vs-configuration test applied at intake (disguised mechanism changes named as such), new mechanisms built once, multi-tenant, even when one brand funds them (the funder gets priority, not exclusivity — unless the portfolio deliberately decides otherwise), and a periodic fork audit: any behaviour that exists for exactly one brand gets justified or generalised. This is the configure-don't-fork argument turned inward, and it compounds identically.
Incidents across the seam
The joint runbook, agreed in peacetime: severity classes shared by both sides; the platform owns diagnosis, fix and the honest timeline; the brand owns player communication and goodwill; compliance owns every regulator contact. The postmortem's output lands as platform improvements and runbook edits — never as a brand-side workaround, because workarounds are forks with an incident as their origin story.
The relationship, reviewed
Quarterly, the same three questions as every seam in the org design: is the boundary being used, bypassed or renegotiated? Bypasses (shadow tools, side-deals, disguised requests) mark boundary errors; renegotiations are healthy when explicit. The platform-brand relationship is the multi-brand group's marriage — it does not need to be frictionless, it needs its arguments refereed by rules both sides helped write.
Continue reading: Scaling operations — how this seam industrialises with brand count. Shared services — the operating form of the platform side.