Skip to content

Architecture

Governance Metrics

1 min readEdit on GitHub

Governance requires measurement.

The ACC provides a finite set of capabilities against which the enterprise can measure authorization risk, accountability, policy coverage, observability, and compliance. This makes it possible to define governance metrics using capability_id as the common unit of analysis.

The specific GovOps metrics should be developed separately and refined through implementation experience. Metrics should generally be aggregated by attributes already present in the ACC, such as risk tier, business impact, geography, business function, data sensitivity, or third-party exposure.

The purpose of GovOps metrics is not to prescribe a fixed dashboard. It is to establish a common measurement model in which governance questions can be answered across otherwise unrelated applications and infrastructure.

The final set of metrics, their definitions, and any recommended key performance indicators are being developed as a separate GovOps deliverable.