Where two or more controllers jointly determine purposes and means, they are joint controllers and must set out their respective data protection tasks and responsibilities transparently in a contract (unless the law already defines them), aimed at protecting data subjects. Data subjects may exercise their rights against any of them; they are jointly and severally liable to the Authority and to data subjects; each must meet the obligations it assumed and keep evidence available to the Authority, and each is sanctioned according to its responsibilities; the agreement must be shared with data subjects who ask for it.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.