The Workload Sovereignty Matrix

Frameworks / The Workload Sovereignty Matrix

The Workload Sovereignty Matrix


Sovereignty is usually debated as a binary and a compliance problem. It is neither. It is a per-workload decision — and answering it once, globally, is the expensive mistake.

Most organisations treat sovereignty as a single switch: either we keep everything in-country and in-house, or we do not. That framing turns a nuanced set of decisions into one blunt policy, and the policy is always wrong for some large fraction of the estate — too restrictive for workloads that could safely run anywhere, too lax for the few that genuinely cannot. The matrix exists to replace the single switch with a decision made workload by workload.

The two axes that actually decide it

Strip the debate down and two dimensions do most of the work. The first is sensitivity — how much the data’s gravity, regulatory exposure, and the cost of being wrong pull a workload toward tight control. The second is portability — how easily the workload could technically run elsewhere, given its latency tolerance and integration dependencies. Neither axis alone tells you where a workload should live. Together, they place it.

sensitivity → portability → Keep sovereign high sensitivity, low portability Negotiate carefully high sensitivity, high portability Hold, but revisit low sensitivity, low portability Run anywhere low sensitivity, high portability

The corners tell the story. High sensitivity and low portability is the only true sovereign workload — keep it, deliberately, and pay for the control. Low sensitivity and high portability should run wherever it is cheapest and best; treating it as sovereign is pure waste. The interesting decisions live in the other two corners, where sensitivity and portability pull in opposite directions and the answer has to be reasoned, not defaulted.

How to see it in the field

The tell is a single sovereignty policy applied uniformly across the whole estate. If the same rule governs the customer-data platform and the internal meeting-notes summariser, sovereignty is being treated as identity rather than as a decision — and the organisation is almost certainly over-controlling cheap workloads while under-examining the genuinely sensitive ones.

A second tell: the decision was made once, at a board offsite, and has not been revisited since — even as data volumes, regulations, and vendor terms have all moved. Sovereignty answered once and frozen is sovereignty answered wrong, because every input to the decision keeps changing.

Getting out of it

Take the estate workload by workload and place each one on the two axes. The exercise itself is the value: it forces you to say out loud how sensitive each workload really is and how portable it really is, and it usually reveals that the truly sovereign set is far smaller than the blanket policy assumed. Concentrate control and cost where the matrix says it belongs, and free everything else.

Then make it a standing review, not a one-time sort. A workload’s position moves as its data grows, its regulation tightens, or its portability improves. The matrix is not a filing system; it is a decision you re-run as the inputs change.


Developed in the book Who Controls Your Intelligence? Related: the Intelligence Control Stack.