How it works
To govern anything in Domino, it must be in a bundle, and every bundle originates in a Project. Policies applied to the bundle define what compliance looks like, and Domino tracks the bundle against them:- Bundles hold the materials or work items you want to govern as a group, such as models, files, and Apps.
- Policies define the governance lifecycle a bundle must go through: all stages, evidence, and approvals required for compliance. Policies are fully customizable, so they can reflect your internal compliance processes (a “Data Privacy Policy” or “Infosec Policy”) as well as industry frameworks (“NIST AI RMF” or “SR 11-7”). A bundle can carry multiple policies, and a policy can be reused across bundles.
- Stages are the phases you expect work to go through, for example Use Case Definition, Data Selection, Deployment, and Ongoing Monitoring.
- Evidence is the information each stage requires, collected as static responses, attachments, or computed results. Domino can generate much of it automatically.
- Approvals specify who must sign off on the provided evidence before a stage is complete. Approvals can also control transitions between stages.
- Gates enforce that certain actions, such as deploying an App or Agent or using restricted hardware tiers, cannot be performed until the required approvals are complete.
- Findings document issues discovered while reviewing evidence, so they can be tracked to resolution.
Who does what
Governance uses role-based access built on existing Project permissions, plus one new global role:- Practitioners create bundles, add artifacts and evidence, and submit bundles for review, all through their existing Project permissions.
- Approvers review evidence, approve stages, and create findings to document issues.
- Governance Administrators (the GovernanceAdmin global role) create, edit, and publish policies, and have access to compliance views, the Audit Trail, and Governance APIs.
Platform-wide accountability
Beyond bundle reviews, the Audit Trail records user activity across your entire Domino deployment for compliance verification, security investigations, and audit reporting, with purpose-built UI views and APIs. Domino retains audit data for up to 30 years, depending on your deployment’s retention policy.Work with Governance
- Work with bundles: Connect assets to policies and start the governance workflow.
- Define policies: Create and configure policies (for Governance Administrators).
- Evidence: Configure manual and automated evidence collection.
- Approvals: Define who must sign off, and when.
- Gating: Block deployments until approvals are complete.
- Roles and security: Understand permissions and role assignment.
- Audit Trail: Review the log of user and system actions across the platform.
- FinOps: Manage and attribute the cost of work on the platform.
- Governance glossary: The full governance vocabulary.