Most data governance initiatives stall not because the tools are missing, but because the program never becomes operational. Policies live in documents, ownership is ambiguous, and the connection between discovery, access control, and audit is manual. The DG Foundation track is designed to get past that — to a running baseline you can defend in an audit — in about thirty days.
What a “baseline” actually means
A governance baseline isn't a finished program; it's the smallest version that stands on its own. Concretely, at the end of the first phase you should have:
- Your highest-priority data domains modeled and connected;
- Owners and stewards assigned, with explicit authority;
- Policies and controls recorded against the assets they govern; and
- Audit-ready lineage on every governed asset.
The scope is deliberately narrow. You are not trying to govern everything — you are proving the loop closes for the data that matters most.
Week 1 — Connect and scope
Deploy Procela's edge connector inside your environment and connect your databases, warehouses, and dbt — sources like PostgreSQL, SQL Server, Oracle, Snowflake, BigQuery, Redshift, and Databricks. Only metadata leaves your perimeter. In parallel, pick the domains for Phase 1 — usually the ones under the most regulatory pressure, such as CUI, PII, or export-controlled engineering data.
Week 2 — Classify and reconcile
Register your in-scope assets and let Procela's AI suggest classifications, then reconcile them against your chosen domains. The AI-assisted suggestions are review-gated, so a steward confirms anything unlabeled before it takes effect. The goal here is coverage: every asset in scope has a known classification and a home domain.
Week 3 — Assign stewardship
Map owners, stewards, and agents to domains and assets. Procela derives a RACI matrix from those role and process-ownership assignments, so accountability is explicit rather than implied. This is the step most programs skip — and the reason audits turn into fire drills later.
Week 4 — Govern and audit
Author your first policies in plain language and record the controls that implement them — access, retention, export controls — against the assets they govern. Every change lands in a tamper-evident audit trail, so audit prep becomes a query rather than a project.
Common pitfalls
- Boiling the ocean. Trying to govern every domain at once guarantees you finish none. Phase 1 is a wedge, not the whole program.
- Ownership by committee. If everyone owns a domain, no one does. Assign a single accountable owner per domain.
- Policies without owners or controls. A policy that isn't recorded against a governed asset, with an accountable owner and the control that implements it, is just documentation.
After Phase 1
Once the baseline is live, expanding is mostly a matter of adding domains — the catalog, stewardship model, and audit trail are already in place. The hard part, going from zero to a running program, is behind you.