Who is responsible
For companies that distribute software and inherit its license obligations
If third-party code, fonts, icons, or SDKs are in what you ship, your organization has legal duties whether or not anyone has documented them.
Last updated: July 2, 2026
01Who owns the duty?
SaaS, desktop, mobile, on-prem, appliances, embedded. The delivery model changes which obligations bite hardest, not whether obligations exist.
Legal / compliance / OSPO
Owns whether publish and distribution steps satisfy each obligation. Needs a maintained record to share with procurement, not a stale spreadsheet or a dashboard only engineering can read.
Product / customer success
Owns the enterprise deal when buyers ask for proof. Defensible disclosure they can verify release to release, not an ad-hoc snapshot sent under deadline.
Engineering / release
Owns what actually ships, and keeps attribution files, SBOM imports, and pipeline checks aligned with the published page.
When this applies
- Multi-product vendors. Each shipped product carries its own obligation set
- Teams asked to prove third-party license posture in security reviews and procurement
- Organizations tired of discovering GPL, missing required attribution, or invisible fonts after ship
Outside scope
- Pure services with no bundled third-party materials and no distributable artifact
- One-time legal opinions with no inventory tied to what engineering releases
Continue reading
Related topics
One idea per page: Follow the path that matches your next question.