Most data governance initiatives stall not because the tools are missing, but because the program never becomes operational. Policies live in documents, ownership is ambiguous, and the connection between discovery, access control, and audit is manual. The DG Foundation track is designed to get past that — to a running baseline you can defend in an audit — in about thirty days.
What a “baseline” actually means
A governance baseline isn't a finished program; it's the smallest version that runs on its own. Concretely, at the end of the first phase you should have:
- Your highest-priority data domains modeled and connected;
- Owners and stewards assigned, with explicit authority;
- A working policy layer that propagates to your enforcement tools; and
- Audit-ready lineage on every governed asset.
The scope is deliberately narrow. You are not trying to govern everything — you are proving the loop closes for the data that matters most.
Week 1 — Connect and scope
Deploy Procela Edge Agents inside your environment and connect your existing discovery, catalog, and access-control tools. Only metadata leaves your perimeter. In parallel, pick the domains for Phase 1 — usually the ones under the most regulatory pressure, such as CUI, PII, or export-controlled engineering data.
Week 2 — Classify and reconcile
Pull classified assets in from tools like BigID and reconcile them against your chosen domains. Let Procela's agents propose classifications for anything unlabeled, routed for review at the autonomy tier you're comfortable with. The goal here is coverage: every asset in scope has a known classification and a home domain.
Week 3 — Assign stewardship
Map owners, stewards, and agents to domains and assets. Procela distributes assignments automatically based on your org structure, so accountability is explicit rather than implied. This is the step most programs skip — and the reason audits turn into fire drills later.
Week 4 — Govern and audit
Author your first policies in plain language. Procela translates them into enforceable rules and propagates them to your enforcement tools — access, retention, export controls. Every change and access event lands in a tamper-evident log, so audit prep becomes a query rather than a project.
Common pitfalls
- Boiling the ocean. Trying to govern every domain at once guarantees you finish none. Phase 1 is a wedge, not the whole program.
- Ownership by committee. If everyone owns a domain, no one does. Assign a single accountable owner per domain.
- Policies without propagation. A policy that isn't wired to an enforcement tool is just documentation.
After Phase 1
Once the baseline is live and self-maintaining, expanding is mostly a matter of adding domains — the orchestration, stewardship model, and audit trail are already in place. The hard part, going from zero to a running program, is behind you.