Topic
Data Governance
4 entries filed under this topic
Data Governance — behaviour with evidence, not policy on paper
Data governance is a set of decisions about data plus the evidence those decisions are being lived — not paper. Cordata's operating-model half of the Fabric + Mesh Hybrid, with the DORA shift that changed personal accountability, federated computational governance as the answer, and the DACH hooks (BaFin § 25b, Betriebsrat, DSGVO Art. 28-30) it has to survive.
The catalog is the API — a governed mesh over MCP
The Fabric + Mesh reference ended with a promise: an MCP-exposed catalog tool that answers which sensitivity level applies to a column holding an EU IBAN, from the live LF-tag policy rather than a stale wiki. This is that design. Tools versus Resources as the decision the whole thing hinges on, output schemas derived from the descriptor model already published, why a read-only envelope has to be enforced rather than annotated, and why authorization — not the tool list — is the governance plane. Verified against MCP revision 2026-07-28.
The pipeline half, part 2 — OpenLineage, Great Expectations, and the evidence a pipeline emits
Part 1 covered what a pipeline reads. This part covers what it emits, and why that is the whole governance story: OpenLineage as the vendor-neutral lineage backbone, the AWS-native adoption playbook via DataZone's PostLineageEvent API, assertion results as a data-quality facet a grant can be suspended on, and the provenance facet that answers the auditor's 'which code produced this number'. Plus why the scheduler stays central while compute decentralises, and the one hop this architecture cannot see. Real payloads and real emitter config throughout.
Behaviour-first governance in practice — generating artefacts from platform events
The Data Governance pillar established the concept: artefacts are byproducts of behaviour, not deliverables in themselves. This post walks the four mechanisms that make it real — RoPA from lineage, RACI from catalog ownership, audit report from subscription log, and a change-authorisation workflow where the commit is the evidence. Real Terraform, SQL, and YAML throughout.