How Big is Your Project?
Governance isn't one-size-fits-all — a weekend experiment and a payroll integration are not the same thing.
The five lanes
-
Explore
Learning, prototyping, personal tools. Non-sensitive data only. Light governance: the account rule and data rules still apply; almost nothing else does. Most projects should start here — and many happily stay.
-
Pilot
A team-scoped trial with exit criteria: what does success look like, and when do we decide? Real users, limited blast radius, an agreed end date for the experiment.
-
Non-Enterprise Production
A department relying on your app for real work, at limited scope. Now upkeep, review, and support expectations are real — this is where “who owns what” earns its keep.
-
Advisory / Connected
Sensitive data or connections to enterprise systems, with a human in the loop. Defined requirements apply — see using university resources.
-
Enterprise Production
Full governance, automated operations, institutional stakes. This is professional IT territory, whoever builds it.
The question that sorts it
“If this fails badly, who's affected?”
Just you? Explore. Your team, recoverably? Pilot. A department's daily work? That's production, whatever you've been calling it. People's sensitive data or an enterprise system? You're in the heavy lanes, and the guardrails exist for exactly this case.
Pre-flight: three questions before you ship
- Which lane am I in? Actually in — not aspirationally.
- What's the data classification? Public, Internal, Sensitive, or Restricted — of the data and the code.
- Has it been reviewed for the lane it's in? Not the lane you wish it were in.
These three catch roughly 80% of governance issues before they happen. The other 20% is what office hours is for.