The "Goldilocks" Data Governance Team

The "Goldilocks" Data Governance Team
Photo by Hans-Jurgen Mager / Unsplash

How to size and structure a data governance team to be juuuuust right.

The calendar invite said "Enterprise Data Governance Council - Monthly Sync." Thirty-four names on the invite list. Nineteen joined. The first six minutes were spent confirming that everyone could, in fact, see the screen.

Then came the deck. A title slide, a "wins" slide, and a RACI matrix rendered in seven-point font that I am confident has never been read by a human being, including the person who built it. Someone gave a status update. Someone else gave a status update about the first status update. In the chat, three people apologized in advance for their hard stops.

Agenda item four was the one that actually mattered: approving a single, unified definition of "Active Customer." It was tabled for the third consecutive month because "the right people weren't on the call."

Nineteen people were on the call. Somehow, none of them were the right ones.

I did some quiet math against the salaries in that virtual room and estimated we had just spent roughly $4k to not define two words. This council had existed for over a year. Its total output to date: a charter, a logo (yes, a logo), and a glossary that had been "in review" for eleven months. Not one definition applied. Not one report changed. Not one metric reconciled.

Thirty people cannot steer a canoe.

Goldilock's verdict? Too big, too cold!

a bowl of cereal with a spoon in it
Photo by Mona Bernhardsen / Unsplash

I've lived the other extreme too, and at the time — it felt amazing.

Three of us. One whiteboard. An agenda that fit on a sticky note. In six weeks we unified the revenue definition, collapsed four competing versions of "customer count" into one, AND shipped a data dictionary that people could actually read. Decisions took minutes instead of quarters. We were light, nimble, and decisive — everything that thirty-person council was not. I remember thinking, this is what data governance is supposed to feel like.

Then the next quarter arrived.

The regional ops leads rejected the new staffing metrics because "nobody asked us." Finance quietly kept their own spreadsheet version of revenue, which is how you know the spell is breaking: the feudal Excel castles start rebuilding themselves overnight. Adoption cratered. Within ninety days we had rolled back half of what we shipped, and the definitions we fought so hard for became "that thing the data team tried last year."

We had the authority to decide. We didn't have the buy-in to make anything stick. It turns out you can be fast, correct, and completely ineffective, all at the same time.

Goldilock's verdict? Too small, too hot!

a person stirring food in a pot on a stove
Photo by Sonia Nadales / Unsplash

Two teams. Two failures. The same story, served at two temperatures.

What I've found is that it's not about the size of the meeting, but the shape of the work.

The big enterprise council assumed that governance happens in a conference room and it invited everyone who might ever be affected. Consensus at that scale isn't consensus — it's a universal veto. Every seat at the table is another hand that can stop the music, and inclusion becomes political cover for inaction. The three bears' porridge isn't just lukewarm. It's been sitting out so long it's grown a skin.

The tiny team assumed that governance is a decision problem, when it's mostly a communication problem. I've written before that Data Governance is somewhere between 80 and 95 percent communication and a three-person team, no matter how sharp, simply doesn't have enough surface area to carry decisions into every corner of the business. That porridge is scalding. The organization takes one bite and pushes the bowl away.

Goldilock's Diary: Two Bad Bowls
The thirty-person council is the porridge that's gone cold: too many cooks, too many hands on the spoon, and by the time anyone agrees it's edible, nobody wants it. The three-person team is the porridge straight off the stove: fast, sharp, and impossible to actually swallow. Size isn't the villain in either story. The question isn't "how many people?" rather, it is "will the organization actually eat what we serve?"

So what's juuuuust right?

Here's the reframe: the Goldilocks answer isn't a headcount, it's a shape. Specifically, it's a cycle with four phases: Define, Apply, Monitor, and Discover. Only one of those phases happens in a conference room.


Define: The Only Phase That Happens in a Meeting

The governance team, the actual named-on-the-charter team, convenes for exactly one purpose: to Define. Definitions of terms. Standards for quality. Rulings on conflicts. Priorities for the quarter. This is the meeting where "Active Customer" gets one definition, an owner, and an effective date and importantly ... then the meeting ends.

Who sits at this table? Fewer people than you think:

  • One chair. Usually your data leader. Sometimes backed by your PMO. Runs the agenda, documents the decisions, owns the follow-through.
  • One Data Owner per domain. Not per department — per domain. Finance, Sales, Operations, Marketing, HR. If two departments argue about the same numbers, they share a domain, and they share a seat.
  • Data Stewards on call. The voice of the people doing the hands-on work. Rotate them in, but only if they're reporting out or contributing to an agenda item.
  • One seat for security and compliance. Because finding out about PII requirements after you've defined the dataset is a special kind of pain.
  • One executive sponsor. On speed-dial, not on the invite. Their job is to break ties and clear roadblocks, not to attend. An executive who attends every governance meeting becomes the only voice in it. Your sponsor can also represent the read-out to your executive team.

That's somewhere between six and ten seats, depending on how many true domains your business has. Small enough to decide. Representative enough that the decision survives contact with the organization.

Goldilock's Diary: Seats vs. Invitations
A seat is not the same thing as an invitation. Keep voting seats small, then publish the minutes and decision log to everyone. Observers can join with mics muted. Comments can flow through the Discover queue (more on that below). The meeting is sized to decide; the communication is sized to inform. The moment those two things swap, you're building the thirty-person council again.

And what fills the agenda? Not status updates. Every item comes off the Discover queue: real friction, submitted by real people, requiring a real decision. If the queue is empty, skip the meeting! Nothing erodes a governance program faster than a recurring meeting held out of momentum. Governance theater is still theater, and everyone in the audience knows it.


Apply: The Owners Carry It Home

Between meetings, the Data Owners take the decisions back into their domains and make them real. The semantic layer gets updated. The certified dataset changes. The measure gets renamed, the old one deprecated, the report footer updated, the team notified in the channel where they actually live.

Notice who's doing this. Not the data team, parachuting into a domain they don't own, changing numbers on people who never saw it coming. The owner — the person who sat in the room, represented the business, made the argument, won some and lost some, and walked out holding a decision they helped shape. When their department pushes back (and someone always pushes back), the answer isn't "the data team changed it." The answer is "we changed it, and here's why."

That sentence is the difference between my three-person team's rollback and a change that holds. Distributed enablement survives over executive decisions.

Goldilock's Diary: The Effective Date
Every Define decision ships with three things: the definition, the owner, and the effective date. "We'll roll it out when things calm down" is how a decision becomes a suggestion. Things never calm down.

If you're changing a metric, create a new field and cut-over on the effective date, while preserving history in the old field so reports don't fail overnight.

Monitor: The Stewards Watch the Ground

While the Owners apply, the Data Stewards watch. Is the new definition actually being used, or is a shadow version quietly circulating in a workbook named: revenue_FINAL_v3_USE_THIS? Are the data quality checks passing? Did usage on the certified dataset go up — or did three new rogue extracts appear in its place?

This is the phase my nimble little three-person team never had. We shipped the change and moved on, assuming the value was self-evident. Nobody was walking the house, so nobody noticed that somebody had been eating our porridge until the quarter-end review made it everyone's problem. Monitoring isn't glamorous. It's the bears coming home and checking every bowl, every chair, every bed — because the intruder never announces herself. You find her by noticing what's been disturbed.

Goldilock's Diary: What Stewards Actually Watch
Three signals, checked on a cadence: usage metrics on certified datasets (are people using the blessed source?), data quality drift (is the blessed source actually right?), and exception requests (how many "one-off" deviations from the standard?). Any one of them trending the wrong way is on it's way to your next meeting agenda.

Discover: The Queue That Feeds the Machine

Finally, Discover — the phase where Stewards and Owners collect what the organization is trying to tell them. The metric two teams calculate differently. The new source system nobody classified. The term that means three things in four departments. The exception request that keeps getting asked, which means it isn't an exception anymore, it's an unwritten rule waiting for a decision.

All of it flows into a queue; anyone can submit. The chair performs triage and the queue becomes the agenda for the next Define meeting, which closes the loop and starts the cycle again.

This is the hub-and-spoke model I've written about before, set in motion. The hub defines. The spokes apply, monitor, and discover. The meeting stays small because the work was never supposed to happen in the meeting.


Not Too Big, Not Too Small

So here's the resolution to the Goldilocks problem, and it's a little sneaky: the right-sized governance team is both sizes at once.

The room stays small: six to ten seats, agenda from the queue, decisions with owners and dates. But the team, the real team, is big. Every Data Owner and every Steward carries out the Apply, Monitor, and Discover phases where the work actually lives. Count them all and you might have forty people involved in governance — more than that doomed council of thirty-four ever really had. The difference is that only ten of them are ever in the same meeting, and none of them are giving status updates.

The big council failed because it put all four phases in one conference room and drowned. The small team failed because it kept Define, rushed Apply, and abandoned the other two phases entirely. The Goldilocks Data Governance team splits the difference not by averaging the headcount, but by putting the right number of people in the right phase.

So don't wait for the bears to come home and catch you. Invite them in first. Give each one a seat and a domain. Let them help decide what's in the one bowl everyone's going to eat from. Keep the room small, keep the field wide, and let the cycle turn: Define, Apply, Monitor, Discover.

Not too big. Not too small.

Juuuuust right.

a bowl of oatmeal with berries on top
Photo by Eiliv Aceron / Unsplash