👋 Hey {{first_name|there}},
New arc, six issues, on failures you didn't cause and still have to answer for. Third parties, managed services, the parts of your system that belong to someone else.
We start with the one that sounds too obvious to spend an issue on.
Why this matters
Most companies can produce a list of their third-party providers inside an hour. Procurement keeps it; it's mostly accurate, and it goes to the regulator once a year.
Almost none of them can answer the question that gets asked at nine in the evening with an incident still open. What else depends on that?
Those are different artefacts. One records who you pay. The other tells you what stops working for a customer when something you pay for stops working properly, which is a harder thing to write and a much harder thing to keep current, mostly because keeping it current isn't anybody's job and never appears on a roadmap.
The gap is almost never an unknown vendor. Nobody discovers mid-incident that they've been using a cloud provider. The gap is that "AWS" is a true entry on a register and useless in a war room, while "the fee service can't write to Kafka, so quoting stops, so nobody can trade" is a sentence somebody should have written down eighteen months earlier.
Someone will ask you what else runs on that. They'll ask while the incident is open, and they'll expect an answer in minutes.
🧭 The shift
From: "We have a list of our third-party providers."
To: "We know which customer journeys stop when each one does."
A register is an inventory. What you need is a set of consequences, written per journey, in language somebody outside engineering can act on.