Data quality / FIELD GUIDE

What is Data governance?

Data governance establishes the responsibilities, policies and decision processes for managing data, including its quality, access, meaning, retention and permitted use.

Key takeaways

  • Governance assigns authority and rules for how data is defined, accessed, changed and used.
  • Policies need operational owners and enforceable controls.
  • The same rules should apply across manual work, integrations and AI tools.

Overview

Governance makes ownership and rules explicit. It answers who can change a field, which definition a report uses, how data is retained and what happens when a person requests a correction or deletion. Policies need enforcement in actual systems and workflows. A document without responsible owners or operating controls cannot resolve everyday data conflicts.

How it works

  1. Assign owners and define critical data terms and permitted uses.

  2. Implement access, quality, retention and change-control rules.

  3. Monitor compliance with those rules and maintain a process for exceptions.

Assign decisions to accountable owners

A data policy becomes useful when it identifies who can decide what. An account owner field may belong to sales operations, subscription state to billing and communication preferences to the system that records the user’s latest choice. Governance establishes those authorities so integrations do not settle disagreements by whichever update arrives last.

Define the meaning of shared fields and lifecycle events as well as access rights. If teams disagree about what an active customer means, restricting database access will not make the report consistent. Keep definitions, ownership and change procedures accessible to the people building and operating the workflows.

Governance questions for an operational dataset
AreaDecision to documentControl to verify
DefinitionWhat does the field or event mean?Shared schema and versioned documentation
AccessWho may read or change it?Role and workspace authorization
UseWhich purposes and destinations are allowed?Export and integration rules
LifecycleHow are corrections and removals handled?Propagation, retention and audit behavior

Put policy at the point of action

A written rule that only owners may export contacts needs an authorization check where the export is created. The same applies to a background job or an AI agent calling a tool. User-interface visibility alone is insufficient if another route can perform the operation. Enforce tenant scope and permissions in the service handling the request.

Review new integrations for the data they receive and the actions they can take. Request only the required access and make disconnection meaningful. A revoked connection should not leave scheduled work using an old credential. Keep logs sufficient for investigation while avoiding unnecessary copies of sensitive values or secrets.

Make governance part of routine changes

An illustrative new enrichment field may seem harmless until it changes lead scoring and is exported into an advertising audience. Review the full path: source, meaning, access, destination and retention. The field’s effect is determined by how it is used, not only by its name or where it first appears.

Use a lightweight change record for material schema, source and permission changes. Test corrections, merges and removal requests across connected systems, and assign ownership for failures. Governance should help the team make consistent decisions and recover from mistakes. A document that no integration follows creates administrative work without providing the intended control.

ILLUSTRATIVE EXAMPLE

What this looks like in practice

A revenue team defines customer status as a finance-owned field. Enrichment can suggest company attributes but cannot overwrite that status, and every approved change has an audit record.

Examples explain the concept; they are not reported customer results.

What to check

Check ownership clarity, enforceable permissions and handling of exceptions. Review whether downstream exports retain the restrictions and definitions attached to their source data.

Common mistake

Creating a broad policy while leaving integrations free to overwrite authoritative fields or retain deleted records indefinitely.

Data governance vs. Data quality

Data quality concerns fitness for use. Governance establishes who defines, maintains and enforces the standards and responsibilities that support that quality.

Read the Data quality definition →

Questions answered

What is Data governance?

Data governance establishes the responsibilities, policies and decision processes for managing data, including its quality, access, meaning, retention and permitted use.

Is governance only for large enterprises?

No. Even a small team benefits from clear field ownership, access rules and retention decisions. The process can be proportional to the size and risk of the system.

Who should own governance?

Assign business owners for meaning and permitted use, with technical owners implementing controls. Shared responsibility works best when each decision still has a named accountable role.

Is data governance only a compliance function?

No. It also supports consistent reporting, reliable integrations, clear ownership and safer changes. Legal and contractual requirements can inform governance, but many everyday governance decisions concern which system owns a field, who can correct it and how downstream workflows should interpret it.

How should governance apply to AI agents?

Give agents the same scoped access and action rules as other application components, with clear task boundaries and observable operation receipts. A model should not decide its own permissions from retrieved text. Review consequential actions and preserve evidence according to the workflow’s established controls.

References and further reading

Primary documentation and source material for this topic. Sources checked September 14, 2026; provider requirements can change.

  1. What is data governance?IBM
  2. Data minimisationUK Information Commissioner’s Office

    UK-specific guidance. The ICO flags this page as under review following legislative changes.

Continue reading on the blog

Explore all articles and guides →

Put the concept to work.

Explore the relevant AstroFabric workflow and see how the pieces connect.

Help keep this guide useful. Suggest a correction or browse the full glossary.