Put the fifty best classical musicians in the world in one room and tell them to play. The first violinist knows exactly how the melody should breathe. The timpanist is right about the dynamics. The oboe is right about the tempo, and the cellos are right that the whole thing should be slower and darker than any of them are playing it. Every one of them is playing beautifully, and no two of them agree. What you get is not music – it’s fifty correct answers at once, and no one in the room whose job is to say which one wins.

That’s the part people forget about an orchestra. The genius isn’t only in the playing. It’s in the one person who doesn’t play a note – who stands where everyone can see and sets the single reading the whole room then follows. Take that person away and the talent doesn’t resolve into music. It just gets louder.

Now something harder than a symphony. In 1962 Kennedy fixed a target: a man on the moon and home again before the decade was out. It’s remembered as ambition. It was closer to fear – the Soviets were ahead in space, and being second had become a threat. Kennedy couldn’t build a rocket or calculate an orbit. That wasn’t the point. His job was to look at the threat and fix the goal it demanded, and let the thousands who knew how organize around it.

A conductor fixes the reading. Kennedy fixed the goal – and he fixed it against something: a threat that made how far they had to go non-negotiable. Different acts, the same role: the one person who names the point everyone else organizes around, and owns it. Not the most expert in the room. The most accountable.

Hold that – the one who sets the point and owns it – against a question most organizations face without it. The question is: how sovereign does this system need to be?

The question nobody owns

How sovereign does this system need to be? It sounds like one question. In an organization it is really several, asked by different people who rarely sit together.

Take three, just to see the shape. Legal says anywhere a foreign jurisdiction could reach this data is unacceptable. Finance says the version that guarantees that costs twice as much, and that number is unacceptable. The business owner says if it’s slow or down there’s nothing left to protect. Security, compliance and the board have their own. Each is right, each defending something real, and each answering a slightly different question – which is why they never land on the same number.

In the orchestra, musicians disagreeing about tempo is normal – it is what an orchestra sounds like before the conductor lifts the baton. The disagreement isn’t the problem. The problem is when there is no baton. And for this decision, in many organizations, there isn’t one. No one was ever made the person whose call is final on how sovereign a system must be.

There is a name for that person: the Decider, the “D” in the RAPID model, from the old Harvard Business Review question, “Who has the D?” Its point is that decisions go wrong less from bad reasoning than from no one clearly holding the call – so it loops, stalls, or gets made by whoever has the most pull. Which is what happens with sovereignty. The question doesn’t get decided. It gets absorbed – into the loudest voice, the biggest budget, or the architecture that got built before anyone asked.

This isn’t a fringe worry anymore. Microsoft’s own sovereignty guidance now tells organizations to appoint a senior executive to own sovereignty outcomes, with a cross-functional team around them to weigh the trade-offs. It’s good advice. But notice what it quietly admits: if the guidance has to tell you to create this role, it’s because the role usually isn’t there. No one writes guidance reminding companies to appoint a finance chief.

Why no one owns it

Part of the reason is structural. Sovereignty isn’t one department’s problem – it’s every department’s. Legal has a stake in the jurisdiction. Finance has a stake in the cost. Security has a stake in the protection, operations in the uptime. The trouble isn’t that the decision has no home. It’s that it has too many – each function holds a piece of it, each with a legitimate claim, and none of them is in charge of the whole. Shared ownership, no owner.

And fixing that is harder than it sounds, because a single owner needs authority over trade-offs that currently sit with other people – the standing to overrule finance on cost, or security on control, when the call demands it. That authority has to be granted. It doesn’t accrete on its own, and the people who’d hand over a veto to create it rarely rush to.

So the fix is the unglamorous one: someone has to be handed this decision, named and backed. That’s what Microsoft’s guidance, and the governance frameworks, now say – and they’re right.

But here’s the part they leave out, and it’s the part that matters. Naming the owner doesn’t make the decision easy. It makes it possible, which is not the same thing. Because whether a system needs to be sovereign at all – and if so, how sovereign – isn’t a fact you can look up. It’s a judgment. And judgments can be made carefully, by exactly the right person, and still be contested, still need revisiting, still turn out wrong.

If you want to see how hard that judgment is, watch what happens when someone tries to standardize it. The European Union is doing exactly that.

What the EU found out

Under its proposed Cloud and AI Development Act (CADA), the European Union gives the decision a formal home: a public authority runs a risk assessment, a shared framework of four assurance levels sets what each activity requires, and procurement is tied to the result – with room to depart where no suitable service exists. It is a serious, careful attempt to turn this judgment into something orderly. If anything could, it’s this.

And even so, a shared framework doesn’t produce a shared answer. Each member state assesses its own systems, so the same kind of service could still land at different levels in different countries – which is why the Commission can step in where a level looks too low. It has happened before: when the EU’s NIS2 cybersecurity rules were transposed into national law, ENISA and industry bodies documented divergence between countries working from the same framework. Not because anyone did it wrong – the judgment underneath was always a national one.

Which is the quiet lesson for everyone else. If a decision this carefully structured, backed by law, still comes down to judgment, then the disagreement in your own organization isn’t a sign that your people are difficult or your process is broken. It’s the nature of the question.

Someone has to hold the baton

None of this makes the decision easier. That was never the promise. What it does is locate the real problem, which isn’t the disagreement between legal and finance and the business – that disagreement is healthy, and it’s permanent. The problem is that in many organizations the argument has no end, because no one was ever given the authority to end it.

So before the sovereignty questions everyone reaches for – which provider, which jurisdiction, which controls, how to exit – there is a quieter one that comes first. Not how do we become sovereign. Who decides how sovereign we need to be. Name that person, give them the authority the role demands, and hand them the one thing that makes the judgment possible: a common currency to decide in. Not categories, not labels, not “is this sensitive” – consequences. What specifically happens to us if this is reached, and what specifically happens if it stops. The CFO’s number and the security lead’s veto don’t reconcile as priorities. They reconcile as consequences, weighed by someone whose job is to weigh them.

That person won’t be the most expert in the room. Kennedy wasn’t. The conductor can’t play the violin. Their authority was never knowledge – it was ownership, and the willingness to be answerable for the call.

Everything else in sovereignty is downstream of that. You can map your levers, assess your dependencies, place your workloads, test your exits – and all of it assumes a decision that someone, somewhere, already owned. Get that decision an owner, and the rest becomes work. Leave it ownerless, and the rest stays an argument – won by whoever pushes hardest, settled differently every time.

The question was never only how sovereign you need to be. It was who gets to say so. Answer that first, and everything after it has somewhere to stand.

Originally published on LinkedIn.