Governance that engineers can implement.
Ownership, classification, access and retention expressed as enforceable rules rather than as a policy document — so the control exists in the systems, not only on paper.
Policy that no system enforces
Most organisations have a data policy. Far fewer can show where it is enforced. Classification exists as a document, access is granted ad hoc and never reviewed, and retention is aspirational — which becomes acute the moment AI systems start reading everything at once.
- Nobody can name the owner of a given dataset.
- Access was granted for a project years ago and never revoked.
- Retention rules exist in policy and are enforced nowhere.
- Introducing AI raised access questions nobody could answer.
What we build
Governance implemented as technical controls: ownership recorded, classification applied to data rather than to documents about data, access reviewed on a cycle, and retention enforced by systems.
- A data catalogue with a named owner per dataset
- Classification applied to the data itself and carried through the pipelines
- Access model with periodic review and evidence of that review
- Retention and deletion enforced by systems rather than by intent
- Lineage showing where data came from and where it flows
- Audit evidence produced automatically rather than assembled on request
How it runs
Scoped to the data that carries real risk, so governance stays proportionate and finishable.
- 01Catalogue and assign owners
What datasets exist and who is accountable for each. Datasets nobody will own are candidates for deletion.
- 02Classify by sensitivity
Applied to the data and propagated through pipelines, so a derived table inherits the sensitivity of its source.
- 03Model and review access
Role-based access with a scheduled review producing evidence, rather than permissions accumulating indefinitely.
- 04Enforce retention
Deletion and archival implemented in the systems, so the policy is executed rather than intended.
- 05Produce evidence automatically
Catalogue, lineage and access reviews generate the artefacts auditors ask for, without a scramble.
What changes once it is running
What implementing governance rather than documenting it produces.
Ownership becomes answerable
Every dataset has an accountable owner, which is what makes every other control possible.
Access stops accumulating
Scheduled review reverses the drift where permissions are only ever added.
AI can be permitted safely
Classification and access carried into the data layer is what lets AI read broadly without leaking across boundaries.
Audits stop being projects
Evidence is produced by the platform rather than assembled by people under deadline.
How an engagement is shaped
Scoped by risk. Governing everything equally is how governance programmes stall.
Catalogue and risk scope
Two to four weeks cataloguing datasets, assigning ownership and identifying where sensitivity genuinely concentrates.
Implement controls
Classification, access model and retention implemented for the highest-risk data first.
Operate
Review cycles running, evidence generating, and coverage extended as new systems arrive.
Common questions
The things buyers ask before they commit. If yours is not here, it is a good first question for the assessment.
- Is this a compliance project or an engineering one?
- Both, and it fails when treated as only the first. Compliance defines the rules; engineering makes systems enforce them. A policy without enforcement is a finding waiting to happen.
- Do we need a data catalogue product?
- Not initially. A maintained catalogue with real ownership beats an expensive tool nobody updates. Products earn their place once scale makes manual maintenance impractical.
- How does this relate to our AI plans?
- Directly. AI systems read across boundaries that were previously enforced by the fact that finding data was hard. Governance is what replaces obscurity with actual control.
Who owns your customer data?
If the answer takes more than a moment, the catalogue is the first piece of work.
