Governance Policy
Discussion
A Governance Policy is a Policy that establishes the authority, rules, constraints, responsibilities, and decision processes used to govern an entity, activity, resource, or domain.
A Governance Policy can govern:
-
An Organization
-
A User
-
A Role
-
A Node
-
A Node Set
-
A Test Run
-
An Artifact
-
A Baseline
-
A Catalog
-
A process
-
A decision
-
Another governed subject
A Governance Policy can establish:
-
The governing authority
-
The governed subject
-
The applicable scope
-
The applicable jurisdiction
-
The responsible Roles
-
Permitted actions
-
Required actions
-
Prohibited actions
-
Decision rights
-
Approval requirements
-
Access constraints
-
Change-control rules
-
Versioning rules
-
Retention requirements
-
Evidence requirements
-
Evaluation criteria
-
Arbitration rules
-
Exception processes
-
Escalation processes
-
Enforcement mechanisms
-
Review requirements
-
Effective dates
-
Supersession conditions
A Governance Policy can identify:
-
Its identity
-
Its name
-
Its description
-
Its Version
-
Its governing authority
-
Its governed subjects
-
Its applicable Governance Domain
-
Its applicable Organizations
-
Its applicable Communities of Interest
-
Its applicable Roles
-
Its effective time
-
Its expiration time
-
Its status
-
Its precedence
-
Its dependencies
-
Its enforcement mechanism
-
Its exception authority
-
Its Provenance
-
Its Traceability
Definition
Policy that establishes the authority, rules, constraints, responsibilities, and decision processes used to govern a subject
Source
Adapted from:
-
DIDO Reference Architecture
-
DIDO Reference Implementation Conceptual Model
-
DIDO-TE draft Requirements Register
This definition treats Governance Policy as a specialization of Policy. It adds the authority, responsibility, decision-right, enforcement, and accountability characteristics required for governance.
Note
Every Governance Policy is a Policy. A Policy is not necessarily a Governance Policy.
A Governance Policy differs from a Governance Domain:
-
A Governance Domain identifies the scope within which a governing authority applies governance
-
A Governance Policy establishes rules and decision processes applicable within that scope
A Governance Policy differs from a Requirement:
-
A Governance Policy establishes governing direction, constraints, responsibilities, or decision processes
-
A Requirement states a necessary capability, behavior, quality, or constraint that a responsible subject must satisfy
A Governance Policy can provide the source or rationale for one or more Requirements. The Requirements must state the resulting obligations in objectively verifiable form.
A Governance Policy differs from Acceptance Criteria:
-
A Governance Policy establishes governing rules and authority
-
Acceptance Criteria establish the conditions used to determine whether an evaluated subject or outcome is acceptable
A Governance Policy can require an authority to establish or approve Acceptance Criteria.
A Governance Policy differs from a Verdict:
-
A Governance Policy establishes the permitted Verdict values and the rules for assigning or using them
-
A Verdict classifies a Test Result according to those rules
A Governance Policy differs from a Validation Decision:
-
A Governance Policy establishes who can make the Validation Decision and which criteria apply
-
A Validation Decision records the determination made by applying those criteria
A Governance Policy does not govern effectively unless the policy identifies, directly or through referenced information:
-
An authoritative source
-
A governed subject
-
An applicable scope
-
Responsible Roles
-
Applicable rules or constraints
-
An effective period
-
A means of determining compliance
-
A process for handling exceptions or violations
Multiple Governance Policies can apply to the same subject. The applicable governance framework must resolve:
-
Precedence
-
Overlap
-
Conflict
-
Exceptions
-
Jurisdiction
-
Supersession
A Governance Policy can be represented as natural-language text, structured data, executable rules, or a combination of representations. The representation does not change the governing meaning of the policy.
An automated mechanism can enforce a Governance Policy, but automation does not create the governing authority. The applicable Organization, Community of Interest, or authorized Role establishes that authority.
A change to a Governance Policy can create a new Version. The applicable change-control process should preserve:
-
The previous Version
-
The revised Version
-
The reason for the change
-
The approving authority
-
The effective time
-
The affected subjects
-
The applicable Provenance
-
The applicable Traceability
Example
A DIDO-TE Governance Policy governs the approval and use of a Baseline.
The Governance Policy establishes:
-
The Organization that owns the Baseline
-
The Governance Domain in which the Baseline applies
-
The Roles authorized to propose, review, approve, supersede, or withdraw the Baseline
-
The required Evidence
-
The applicable Acceptance Criteria
-
The required Test Results
-
The permitted Verdicts
-
The process for making a Validation Decision
-
The treatment of failed, incomplete, interrupted, or repeated Test Runs
-
The change-control process for replacing the Baseline
-
The required Provenance and Traceability
An authorized Role applies the Governance Policy when reviewing the Test Results and Evidence associated with a proposed Baseline.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.