| title | GovOps Documentation | ||||
|---|---|---|---|---|---|
| status | draft | ||||
| document_type | overview | ||||
| source_of_truth | false | ||||
| normativity | informative | ||||
| owner | TBD | ||||
| last_reviewed | 2026-09-12 | ||||
| audience |
|
||||
| tags |
|
||||
| related | |||||
| supersedes | |||||
| superseded_by |
Working draft. This documentation set is Vatsal Gupta's personal working draft of a proposed structure for the GovOps Working Group's material. It has not been reviewed or ratified by the group (Mike Schwartz, Rohit Khare, Debayan Basu, and other editors). Nothing here should be read as the group's official position.
If action-resource is the unit of governance, GovOps defines the systems, business processes, and metrics that governors need to manage risk, ensure accountability, and make governance observable. (Purpose statement proposed by Mike Schwartz, 2026-09-12.)
GovOps treats the capability — a stable identifier (capability_id) hashed from group + action + resource — rather than an identity, role, or one-off policy decision, as the primary unit of governance. Identity doesn't disappear; it becomes an input evaluated at decision time, not the thing that gets cataloged, versioned, and audited.
A governance and observability layer that sits on top of whatever authorization decision mechanism you already use (OPA, Cedar, XACML, anything PBAC-capable). It defines a shared, capability-anchored catalog, a lightweight correlation record joining authorization context to application and kernel-level telemetry, and a path from that data to compliance evidence.
- Not an authorization engine specification — it is neutral on policy language/engine.
- Not a replacement for IAM, policy engines, or compliance frameworks.
- Not yet a formal conformance specification (see
06-decisions/ADR-006-conformance-postponed.md). - Not (yet) an operational process guide — see
04-how-to-and-process/README.md.
- Why it exists:
01-explanation/ - What it defines:
02-reference/ - How evidence and compliance mapping work:
03-metrics-and-compliance/ - How to operate it:
04-how-to-and-process/— planned - How to contribute:
05-tutorials/— planned - Why key choices were made:
06-decisions/ - Current scope and open questions:
07-project-and-roadmap/
| Question | Canonical location |
|---|---|
| What does a term mean? | 00-foundations/glossary.md |
| What are the nine services? | 02-reference/components/ |
| What fields make up the information model? | 02-reference/information-model/ |
| How are components connected? | 02-reference/interfaces/ |
| How is compliance evidenced? | 03-metrics-and-compliance/ |
| What is current vs. proposed? | Front matter status field, and 07-project-and-roadmap/ |
- Treat documents with
status: currentas settled; treatdraft,proposed, andplannedas non-normative working material. - Prefer
source_of_truth: truepages over summaries when they conflict. - Resolve terms using
00-foundations/glossary.mdbefore assuming a meaning. - For any design choice, check
06-decisions/for the relevant ADR before treating a reference page as arbitrary. - Do not infer conformance requirements —
02-reference/conformance/README.mdstates GovOps is not yet a formal specification (ACC is the one exception planned to go normative first, later). - Follow
relatedfront-matter links before inferring relationships between services, fields, and controls. - Flag conflicts between pages rather than silently picking one.
- Read this file first.
- Resolve terminology in
00-foundations/glossary.md. - Route the request: rationale/positioning →
01-explanation/; definition/architecture/contract →02-reference/; evidence/metric/compliance mapping →03-metrics-and-compliance/; procedure/operating model →04-how-to-and-process/; learning/onboarding →05-tutorials/; rationale for a specific choice →06-decisions/; unsettled/planned work →07-project-and-roadmap/. - Prefer
status: currentandsource_of_truth: true. - Do not treat
planned,draft,proposed, orinformativecontent as mandatory. - Follow
relatedlinks before inferring relationships. - Flag conflicts rather than selecting one source silently.