Skip to main content
Governance is how you implement your organization’s validation, review, and compliance processes inside Domino. Because reproducibility, auditability, and lineage are built into the platform’s core, governance works alongside development instead of interrupting it: builders keep working in their Projects while Domino collects evidence, tracks approvals, and records what happened. Governance is not tied to any one kind of work or process. Anything developed in a Project can be governed: models, Apps, API endpoints, files, reports, and agents. What compliance means is defined entirely by your policies, whether they reflect an internal review checklist, a corporate standard, or a regulatory framework. Policy-based governance is one facet of Domino’s Governance Center. The others are FinOps, for managing the cost of work on the platform, and the Audit Trail, which records actions taken across the platform.

How it works

To govern anything in Domino, it must be in a bundle, and every bundle originates in a Project. Policies applied to the bundle define what compliance looks like, and Domino tracks the bundle against them:
  • Bundles hold the materials or work items you want to govern as a group, such as models, files, and Apps.
  • Policies define the governance lifecycle a bundle must go through: all stages, evidence, and approvals required for compliance. Policies are fully customizable, so they can reflect your internal compliance processes (a “Data Privacy Policy” or “Infosec Policy”) as well as industry frameworks (“NIST AI RMF” or “SR 11-7”). A bundle can carry multiple policies, and a policy can be reused across bundles.
  • Stages are the phases you expect work to go through, for example Use Case Definition, Data Selection, Deployment, and Ongoing Monitoring.
  • Evidence is the information each stage requires, collected as static responses, attachments, or computed results. Domino can generate much of it automatically.
  • Approvals specify who must sign off on the provided evidence before a stage is complete. Approvals can also control transitions between stages.
  • Gates enforce that certain actions, such as deploying an App or Agent or using restricted hardware tiers, cannot be performed until the required approvals are complete.
  • Findings document issues discovered while reviewing evidence, so they can be tracked to resolution.
A governed bundle: Models, Files, and Data feed into a Bundle, which carries attached policies (NIST AI RMF, SR 11-7, Model Risk Management) and moves through a policy workflow of Ideation, Development, Review, and Retirement.
Governance is not a one-time review. Approvals can be configured to expire and renew on a recurring schedule (periodic revalidation), so every governed entity is resurfaced for review on the cadence your organization requires.
The governance policy workflow: a Governance Administrator creates policies, a Practitioner answers evidence, and an Approver verifies it, producing approvals or findings across three policy stages before gating platform actions like app publishing, model deployment, and restricted GPU usage.

Who does what

Governance uses role-based access built on existing Project permissions, plus one new global role:
  • Practitioners create bundles, add artifacts and evidence, and submit bundles for review, all through their existing Project permissions.
  • Approvers review evidence, approve stages, and create findings to document issues.
  • Governance Administrators (the GovernanceAdmin global role) create, edit, and publish policies, and have access to compliance views, the Audit Trail, and Governance APIs.
See Roles and security for the full permission matrix and role assignment.

Platform-wide accountability

Beyond bundle reviews, the Audit Trail records user activity across your entire Domino deployment for compliance verification, security investigations, and audit reporting, with purpose-built UI views and APIs. Domino retains audit data for up to 30 years, depending on your deployment’s retention policy.

Work with Governance

  • Work with bundles: Connect assets to policies and start the governance workflow.
  • Define policies: Create and configure policies (for Governance Administrators).
  • Evidence: Configure manual and automated evidence collection.
  • Approvals: Define who must sign off, and when.
  • Gating: Block deployments until approvals are complete.
  • Roles and security: Understand permissions and role assignment.
  • Audit Trail: Review the log of user and system actions across the platform.
  • FinOps: Manage and attribute the cost of work on the platform.
  • Governance glossary: The full governance vocabulary.