Deciding what the model handles, what plain code handles, and how the whole thing behaves when a part of it fails.