Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

title GovOps Documentation
status draft
document_type overview
source_of_truth false
normativity informative
owner TBD
last_reviewed 2026-09-12
audience
executives
architects
contributors
AI agents
tags
govops
overview
related
supersedes
superseded_by

GovOps

Working draft. This documentation set is Vatsal Gupta's personal working draft of a proposed structure for the GovOps Working Group's material. It has not been reviewed or ratified by the group (Mike Schwartz, Rohit Khare, Debayan Basu, and other editors). Nothing here should be read as the group's official position.

Purpose

If action-resource is the unit of governance, GovOps defines the systems, business processes, and metrics that governors need to manage risk, ensure accountability, and make governance observable. (Purpose statement proposed by Mike Schwartz, 2026-09-12.)

Core idea

GovOps treats the capability — a stable identifier (capability_id) hashed from group + action + resource — rather than an identity, role, or one-off policy decision, as the primary unit of governance. Identity doesn't disappear; it becomes an input evaluated at decision time, not the thing that gets cataloged, versioned, and audited.

What GovOps is

A governance and observability layer that sits on top of whatever authorization decision mechanism you already use (OPA, Cedar, XACML, anything PBAC-capable). It defines a shared, capability-anchored catalog, a lightweight correlation record joining authorization context to application and kernel-level telemetry, and a path from that data to compliance evidence.

What GovOps is not

  • Not an authorization engine specification — it is neutral on policy language/engine.
  • Not a replacement for IAM, policy engines, or compliance frameworks.
  • Not yet a formal conformance specification (see 06-decisions/ADR-006-conformance-postponed.md).
  • Not (yet) an operational process guide — see 04-how-to-and-process/README.md.

Read by intent

  • Why it exists: 01-explanation/
  • What it defines: 02-reference/
  • How evidence and compliance mapping work: 03-metrics-and-compliance/
  • How to operate it: 04-how-to-and-process/ — planned
  • How to contribute: 05-tutorials/ — planned
  • Why key choices were made: 06-decisions/
  • Current scope and open questions: 07-project-and-roadmap/

Canonical sources

Question Canonical location
What does a term mean? 00-foundations/glossary.md
What are the nine services? 02-reference/components/
What fields make up the information model? 02-reference/information-model/
How are components connected? 02-reference/interfaces/
How is compliance evidenced? 03-metrics-and-compliance/
What is current vs. proposed? Front matter status field, and 07-project-and-roadmap/

Guidance for agents

  1. Treat documents with status: current as settled; treat draft, proposed, and planned as non-normative working material.
  2. Prefer source_of_truth: true pages over summaries when they conflict.
  3. Resolve terms using 00-foundations/glossary.md before assuming a meaning.
  4. For any design choice, check 06-decisions/ for the relevant ADR before treating a reference page as arbitrary.
  5. Do not infer conformance requirements — 02-reference/conformance/README.md states GovOps is not yet a formal specification (ACC is the one exception planned to go normative first, later).
  6. Follow related front-matter links before inferring relationships between services, fields, and controls.
  7. Flag conflicts between pages rather than silently picking one.

Agent retrieval order

  1. Read this file first.
  2. Resolve terminology in 00-foundations/glossary.md.
  3. Route the request: rationale/positioning → 01-explanation/; definition/architecture/contract → 02-reference/; evidence/metric/compliance mapping → 03-metrics-and-compliance/; procedure/operating model → 04-how-to-and-process/; learning/onboarding → 05-tutorials/; rationale for a specific choice → 06-decisions/; unsettled/planned work → 07-project-and-roadmap/.
  4. Prefer status: current and source_of_truth: true.
  5. Do not treat planned, draft, proposed, or informative content as mandatory.
  6. Follow related links before inferring relationships.
  7. Flag conflicts rather than selecting one source silently.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors