Insight · Microsoft Fabric

    What Is Data Governance? A Definition People Can Actually Use

    Data governance is deciding who owns data, what it means, who may use it and how quality is kept - then making those decisions enforceable. A plain definition, the working parts, and where to start.

    Nick de Vrye, CTOPublished 7 September 20266 min read read
    Navy Solv Systems title card reading 'What Is Data Governance?' with a shield and check motif.

    In Short: Decisions, Made Enforceable

    Strip the ceremony and data governance is four decisions, kept: who owns each data domain, what terms mean (one definition of revenue, not five), who may use what (access, privacy, retention), and how quality is maintained (standards, monitoring, response). Governance is making those decisions explicitly, assigning them to named people, and - the step most programmes skip - enforcing them in the platforms where data actually lives.

    A policy document is not governance; it is a wish. Governance is when the platform makes the wish true by default.

    The Working Parts

    Ownership and stewardship. Every domain - customer, finance, product - has a named owner accountable for its quality and meaning, with stewards doing the weekly tending. Committees do not own things; people do. This is the single highest-leverage element, and its absence is why quality problems recur no matter how many cleanups run.

    Definitions. The business glossary, made real: contested terms settled once, recorded where users meet the data - which in the Microsoft world means encoded in semantic models and catalogued in Purview, not parked in a wiki.

    Access and protection. Who may see what, enforced as workspace permissions, RLS and sensitivity labels, with privacy obligations (GDPR, POPIA) mapped to actual controls rather than asserted in policy.

    Quality management. Standards per critical dataset, automated monitoring, and a response path when checks fail - quality as an operated system, not an annual audit.

    Lineage and audit. Knowing where data came from and who touched it, largely automatic once flows run through governed platforms.

    Making It Real Without a Bureaucracy

    The failure mode is universal: a governance council, a 40-page framework, no enforcement, quiet death. The working alternative we implement is deliberately small.

    • Start from felt pain: the two domains where wrong or leaked data costs real money this quarter
    • Name owners for those domains only; give them time, not just titles
    • Settle the contested definitions in those domains and encode them in the certified models
    • Enforce access properly there: permissions reviewed, labels applied, RLS tested
    • Put automated quality checks on the tables that feed decisions, alerting the owners
    • Expand domain by domain on evidence, using Fabric domains to delegate as you grow

    Our Microsoft-stack governance framework and Purview implementation guide cover the tooling detail; the sequence above is what makes the tooling matter.

    The 2026 Forcing Function

    For years governance lost budget battles because its risks were latent. AI ended that: Copilot answers from whatever permissions allow, agents act on whatever definitions exist, and every gap - the overshared site, the five margins, the stale table - surfaces fluently, at scale, to whoever asks. The organisations treating governance as AI readiness are funding in one quarter what advocacy could not achieve in five years. If you needed the executive one-liner: governance is now the difference between AI that answers and AI that embarrasses.

    Sources and Further Reading

    Frequently asked

    The set of decisions and controls that make data trustworthy and safe to use: who owns each data domain, what terms mean, who may access what, how quality is maintained, and how all of that is enforced in the platforms rather than just written in a policy document.

    Governance decides; management executes. Governance says finance owns revenue data, defines what revenue means, and sets who may see salaries. Management is the pipelines, storage and tooling that implement those decisions daily.

    They stay on paper: councils, policies and glossaries with no enforcement in the platforms, no named owners with time to steward, and no connection to problems the business feels. Working governance is small, enforced and attached to real pain - not a binder.

    Microsoft Purview for cataloguing, classification, sensitivity labels and policy; Fabric's workspace, domain and permission model for access; endorsement and certification for signalling trust; and the semantic model itself for definitions. The tools are ready; the decisions are the work.

    It raised the stakes and shrank the timeline: Copilot and agents surface whatever governance allows, fluently, to anyone. Oversharing, missing labels and undefined terms used to be latent risks; AI makes them immediate. Governance is now a prerequisite for AI, not an aspiration after it.