
For two decades, "data governance" has implicitly meant centralized governance: a single council, a single catalog, a single set of policies enforced top-down. That model worked when data lived in a warehouse and changed slowly. It breaks when an enterprise runs hundreds of domain platforms, dozens of SaaS systems, and an AI program that touches all of them.
The answer isn't to abandon governance — it's to redesign it for federation.
What "Trust by Design" means
Trust by Design is a governance posture where accountability is distributed to the domains that produce the data, and a thin central function provides the standards, tooling, and arbitration that make the federation coherent. Trust is not centrally inspected; it is locally engineered and centrally verified.
Three principles anchor the model:
- Domains own their data products. Each domain publishes data as a contracted product, with declared owners, SLAs, definitions, and quality guarantees.
- Central defines the contract, not the content. The central function owns the data product specification, the platform standards, and the cross-domain policies. It does not own the data itself.
- Trust is observable. Every product exposes machine-readable signals — freshness, completeness, lineage, policy compliance — so consumers can decide what to rely on without asking permission.
Why federation outperforms centralization at scale
- Latency — Domain teams make changes in days, not quarters, because they don't queue behind a central council.
- Fidelity — The people closest to the source own the definition. Translation loss drops.
- Resilience — One domain's failure doesn't take the whole governance program down.
- AI readiness — Models can consume contracted data products with confidence, instead of negotiating trust deal-by-deal.
The hard part
Federation only works if the contract is enforced. Without it, "federated governance" becomes "no governance" with extra steps. The central function has to be empowered to reject a non-compliant data product, the platform has to make compliance the path of least resistance, and leadership has to be willing to let local domains say no to bad requests.
Trust by Design is not a softer version of governance. It is a more disciplined one — and it's the only version that scales with the data estate you actually have.
