{"description":"Data Governance Council Operations as a decision-aware workflow. Each quarterly cycle runs as one workflow instance attached to the existing UC-GOV-20 Control item (data governance council oversight; domains=governance_policy_oversight, frequency=quarterly) — it enriches that Control as its execution record and never creates a governing body. It validates the chartered council's charter and membership, runs the annual policy and lifecycle-standards review when due, compiles data-quality and integrity metrics, reviews and approves data-sharing and matching agreements, convenes the council with recorded minutes, and reports data governance status at the defined interval. Upstream, it consumes the prior cycle's archived governance record — the council and data-integrity-board charters (Policy items, policy_type: charter) and membership rosters, the current data-governance policy and data-lifecycle standards library (Policy items), the prior minutes and status report, and the open action-item register (Issue items linked to the Control). Named deliverables: the data-quality and integrity dashboard, the data-management oversight summary, the chair-approved council (and integrity board) minutes, the per-agreement dispositions, and the data-governance status report; the annual branch adds the refreshed policy and standards redlines and the charter and roster amendments. In scope each quarterly cycle: the named business units and data domains, the data governance council (always), and the data integrity board wherever data-matching (Privacy Act computer matching) or new data-sharing requires its review; a metrics-only cycle need not convene the integrity board. Out of scope: bodies and data domains not named in the cycle's scope. Downstream the workflow is self-contained — no separate workflow depends on it — but it chains cycle to cycle: this cycle's archived governance record, filed with the status report, is the next quarterly instance's primary input.","edges":[{"id":"e-validate-charter-and-membership-review-data-lifecycle-policies-and-standards","label":"Annual review due","source":"validate-charter-and-membership","target":"review-data-lifecycle-policies-and-standards","whenValue":"annual_charter_review"},{"id":"e-validate-charter-and-membership-convene-council-and-record-minutes","label":"Standard quarterly","source":"validate-charter-and-membership","target":"convene-council-and-record-minutes","whenValue":"standard_quarterly"},{"id":"e-review-data-lifecycle-policies-and-standards-convene-council-and-record-minutes","source":"review-data-lifecycle-policies-and-standards","target":"convene-council-and-record-minutes"},{"id":"e-review-data-sharing-and-matching-agreements-resolve-agreement-revisions","label":"Revise","source":"review-data-sharing-and-matching-agreements","target":"resolve-agreement-revisions","whenValue":"revise"},{"id":"e-review-data-sharing-and-matching-agreements-convene-council-and-record-minutes","label":"Approved","source":"review-data-sharing-and-matching-agreements","target":"convene-council-and-record-minutes","whenValue":"approved"},{"id":"e-resolve-agreement-revisions-convene-council-and-record-minutes","source":"resolve-agreement-revisions","target":"convene-council-and-record-minutes"},{"id":"e-convene-council-and-record-minutes-report-data-governance-status","source":"convene-council-and-record-minutes","target":"report-data-governance-status"}],"isPublic":true,"metadata":{"capabilities":[],"controlVerbs":{},"controls":["UC-GOV-20"],"department":"operations","domains":["grc"],"library":{"aliases":[],"canonicalUrl":"https://workflow-library.com/all/?w=grc-data-governance-council-operations","contentDigest":"sha256:2c5564bd2edf274e1a4337ed6524ca7a882fedcab9c7b1f2d5715bae74dfca70","prerequisites":{"status":"undeclared"},"provenance":[],"releaseId":"sha256:2c5564bd2edf274e1a4337ed6524ca7a882fedcab9c7b1f2d5715bae74dfca70","schemaVersion":1,"sourceTemplateId":"workflow-library:grc-data-governance-council-operations"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"grc-data-governance-council-operations","source":"coworkcanvas-gallery","standards":["cobit-2019","nist-800-53"],"teams":["operations","privacy","it"]},"name":"Data Governance Council Operations","nodes":[{"data":{"decisionField":"charter_review_scope","description":"Agent retrieves the current charters and membership rosters and checks whether the annual charter and policy review is due; human CDO decides the cycle's review scope","formData":{"fields":[{"key":"charter_review_scope","label":"Charter and policy review scope","options":[{"label":"Annual charter and data-lifecycle policy review is due this cycle","value":"annual_charter_review"},{"label":"Charters stand as-is; proceed with standard quarterly oversight","value":"standard_quarterly"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Resolve whether this cycle runs the full annual charter-and-policy review or the standard quarterly oversight agenda, and confirm each chartered body is validly constituted before it acts. The Chief Data Officer owns the call.\n\n**Decision criteria**\n\nFirst validate standing (applies to both branches): confirm each in-scope charter — the data governance council, and the data integrity board where in scope — still states a clear purpose, defined membership, documented responsibilities, decision authority, and meeting cadence (the NIST 800-53 PM-23 *Data Governance Body* / PM-24 *Data Integrity Board* constitution test). The charters live as Policy items (policy_type: charter) where captured, carried forward on the prior cycle's archived instance; the membership rosters and quorum rules live as documents on that same archived record (there is no Governance Body item type for the roster). Check the roster against chartered seats and flag every vacancy, lapsed term, or changed role-holder; a body below quorum or missing a mandatory seat (e.g., the privacy or security officer on a data integrity board) cannot validly approve agreements. Read the prior cycle's archived governance record — the archive package attached to that cycle's status-report step — for the date the last annual charter-and-lifecycle-policy-standards review completed.\n\n- **Annual charter and data-lifecycle policy review is due this cycle (`annual_charter_review`)** — pick this when the cadence requires it (the last annual review is twelve or more months old, or none is on record) **or** a material gap surfaced: a charter missing a required element, a membership defect needing charter action, or a data-lifecycle policy shown stale against a new regulation or a changed data inventory. NIST PM-24 requires the data integrity board's annual review of its matching programs; COBIT EDM01 requires periodic evaluation of the governance framework. Routes to the policy-and-standards review.\n- **Charters stand as-is; standard quarterly oversight (`standard_quarterly`)** — pick this only when the last annual review remains current (completed within twelve months), every in-scope body meets quorum with no charter defect, and no lifecycle policy is shown stale. Routes straight to convening the council, where this cycle's metrics are compiled.\n\n**Record in AssureSwarm**\n- Submit the decision form on this step: `charter_review_scope` (the branch), the step result citing the charter-constitution check, the roster/quorum result, the last-annual-review date with evidence references, and the cycle's scope (named business units and data domains); and the step's approver record.\n- Link the reviewed charters (Policy items, policy_type: charter) and the roster/quorum evidence documents to this step (document link).\n\n**Exit criteria** — Form submitted; each in-scope charter is confirmed validly constituted or its defect named; the rationale ties to the cadence date and cited evidence; the decision owner is recorded and the unused branch is prunable.","kind":"decision","label":"Validate charter and membership","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"validate-charter-and-membership"},{"data":{"description":"Agent compiles and updates the data governance policy and standards library across the data life cycle and drafts the refreshed charter language; human governance owner reviews for completeness","instructions":"**Objective** — Refresh the data governance policy and standards library across the full data life cycle and draft the charter and roster amendments the annual review requires, so the council adopts a current, gap-closed, regulation-aligned baseline.\n\n**Inputs**\n- The current data governance policy and standards library — Policy items (policy_type: policy | standard | procedure | guideline) with their `version`, `policy_owner`, `next_review_date`, and `framework`/`domains`, whose governed documents attach to each item; the latest approved versions are carried on the prior cycle's archived governance record.\n- The data inventory / catalog and the records-retention schedule — reference documents uploaded to this step (no Data Asset item type).\n- Applicable regulatory obligations for the in-scope data domains (privacy law, sector regulation, the Privacy Act for matching activity, contractual data terms) — reference documents linked to this step (no Obligation item type).\n- The charter-validation findings from the prior step (charter defects, vacancies, role changes) — carried on the validate-charter-and-membership decision form and its linked charter Policy items.\n\n**Procedure**\n1. Map the library against the DAMA-DMBOK / COBIT 2019 APO14 (*Managed Data*) data life cycle and confirm a current, owned standard exists for each stage: collection and creation, classification, storage and access, use, sharing, retention, and disposal. A stage with no standard — or one whose owner has left — is a gap.\n2. Cross-check each policy against the current data inventory and applicable regulation for stale or missing provisions: a classification standard that predates a new data category; a retention rule out of step with the retention schedule or a new statutory hold; a sharing standard silent on the minimum-necessary and purpose-limitation tests.\n3. Draft the amendment to close each gap, naming the driver (regulation, inventory change, incident) and the accountable owner. Version each change as a redline against the adopted baseline so the council votes on a clean before/after, not a rewrite.\n4. Draft the charter amendments the annual review surfaced — purpose, membership requirements, responsibilities, decision authority — for the council and, where in scope, the data integrity board (NIST 800-53 PM-23 / PM-24).\n5. Draft the updated membership roster: propose appointees for vacant seats, correct changed roles, and confirm every mandatory seat (chair, privacy, security, data owners) is named.\n6. Package the redlined policies and standards, the charter amendments, and the roster for governance-owner review ahead of council adoption.\n\n**Record in AssureSwarm**\n- Enrich each existing Policy item and create one for each gap-closing new standard (item create / item field update — set `policy_type`, `policy_owner`, `approved_by`, `version`, `framework`, `domains`, `review_frequency`, `effective_date`, `next_review_date`), and attach the versioned redline document to its Policy item (step document, DOCX/PDF).\n- Draft the charter amendments as updates to the charter Policy items (item field update — the council and, where in scope, the data integrity board Policy items, policy_type: charter).\n- Attach the packaged policy-and-standards redline library, the charter amendments, and the proposed membership roster as the council-adoption package (document upload — the roster has no native field, so it rides as a document).\n\n**Exit criteria** — Every life-cycle stage has a current owned standard or a named gap with a drafted amendment; charter amendments and roster are complete; the data governance owner confirms the package complete, life-cycle-covering, and regulation-aligned, and ready for council adoption.","label":"Review data-lifecycle policies and standards","performedBy":{"primitives":["coach-document-upload","coach-item-create"]}},"id":"review-data-lifecycle-policies-and-standards"},{"data":{"decisionField":"agreement_disposition","description":"Agent compiles new and pending data-sharing and data-matching agreements and drafts a recommendation for each; human approving body decides disposition","formData":{"fields":[{"key":"agreement_disposition","label":"Data-sharing and matching agreement disposition","options":[{"label":"All pending data-sharing and data-matching agreements approved","value":"approved"},{"label":"One or more agreements returned for revision","value":"revise"}],"required":true,"type":"select"}],"resultType":"form","submittedAt":null,"values":{}},"instructions":"**Objective** — Decide the disposition of every new or pending data-sharing and data-matching agreement this cycle: all approved as drafted, or one or more returned for revision. The approving body owns the call — the council for data-sharing agreements, the data integrity board for computer-matching agreements.\n\n**Decision criteria**\n\nBuild the disposition on a per-agreement review; when none are pending, `approved` is the correct empty disposition. Check each agreement against: **purpose limitation and minimum necessary** — the elements shared are the least needed for a stated, lawful purpose (over-broad element lists are the most common defect); **legal authority and basis** — authority to share or match, consent or statutory basis, and, for matching, the Privacy Act / Computer Matching and Privacy Protection Act regime, where a computer matching agreement needs a cost-benefit analysis (unless the data integrity board waives it), an eighteen-month maximum term with a single twelve-month renewal, a published matching notice, and verification with due process before any adverse action (NIST 800-53 PT-8; 5 U.S.C. 552a(o)–(u)); **safeguards** — security controls proportional to the data classification, breach-notification terms, and onward-transfer limits; **retention and disposal** — retention tied to the purpose with certified destruction; and an accountable internal owner plus counterparty diligence.\n\n- **All pending agreements approved (`approved`)** — every pending agreement passes all checks, or none are pending. For matching agreements the data integrity board's cost-benefit and statutory conditions are satisfied and recorded. Routes to council convening.\n- **One or more returned for revision (`revise`)** — any agreement carries a required change: over-broad elements, missing or insufficient safeguards, absent or excessive retention, missing legal basis, or a matching agreement lacking cost-benefit, term limit, or due-process language. Name each returned agreement and its specific required change in the rationale — the revision step works only that list, and compliant agreements are not reopened.\n\n**Record in AssureSwarm**\n- Submit the decision form on this step: `agreement_disposition` (the branch), the step result naming each agreement's per-check result and, for returns, the specific required change, and the step's approver record.\n- Link the agreement register and each agreement reviewed to this step (document link — there is no Agreement/Contract item type, so the agreements and their statutory attributes ride as documents plus this decision form).\n\n**Exit criteria** — Form submitted with a per-agreement disposition; every returned agreement has a named, specific required change; each matching agreement's statutory conditions are recorded; the decision owner is named and the unused branch is prunable.","kind":"decision","label":"Review data-sharing and matching agreements","performedBy":{"primitives":["coach-query-data","coach-document-upload"]}},"id":"review-data-sharing-and-matching-agreements"},{"data":{"description":"Agent applies the required changes to returned data-sharing and matching agreements and re-routes them for sign-off; human approver confirms the revisions now meet policy","instructions":"**Objective** — Apply the approving body's required changes to each returned agreement and re-route it for sign-off, so every agreement recorded this cycle demonstrably meets policy and regulation — without reopening the ones already approved.\n\n**Inputs**\n- the step result from the decision: the returned agreements and the specific required change per agreement.\n- The returned agreement drafts and the versions the approving body reviewed.\n- The data governance policies and standards and the applicable privacy and regulatory requirements.\n- Counterparty and internal-owner contacts.\n\n**Procedure**\n1. Translate each required change into concrete redline edits: safeguard clauses, purpose limitation, data-element minimization, retention and disposal terms, or — for matching agreements — cost-benefit, term-limit, and verification/due-process language.\n2. Apply the edits and keep a revision log showing what changed, why, and against which reviewed version, per agreement.\n3. Re-run the policy and regulatory cross-check on each revised agreement to confirm the change closed the identified gap without opening a new one (e.g., a tightened purpose that now excludes a data element still listed).\n4. Re-route each revised agreement to the counterparty and the approving body for confirmation, securing counter-signature where terms changed materially.\n5. Hold any agreement that cannot be brought into compliance out of this cycle's approved set rather than forcing it through — record it as deferred with its open issue.\n\n**Record in AssureSwarm**\n- Attach the revised agreements and the revision log, marking superseded drafts as replaced (document upload).\n- Record the re-route in the native step result, the designated approver’s confirmation in native approvals, and any counter-signature on the revised agreement document.\n\n**Exit criteria** — Every returned agreement is revised with a complete revision log and a passing re-check, or explicitly deferred with its open issue; the designated approver confirms the revised set meets the data governance policies and applicable regulation and is ready to record as approved for this cycle.","label":"Resolve agreement revisions","performedBy":{"primitives":["coach-document-upload","coach-form-fill"]}},"id":"resolve-agreement-revisions"},{"data":{"description":"Agent compiles the data-quality and integrity dashboard and oversight summary, assembles the council packet, and drafts the minutes; the council takes the decisions and its chair approves the minutes as the official record","instructions":"**Objective** — Produce the cycle's data-quality and integrity package, convene the chartered council (and the data integrity board where in scope), and work the agenda to recorded decisions and chair-approved minutes that stand as the official governance record.\n\n**Inputs**\n- The data-quality metric feeds for each in-scope data domain, their defined thresholds / service levels, and the prior cycle's results, for trend.\n- The control inventory and the prior cycle's findings with remediation status — open Issue items (source: management_identified) linked to the anchor UC-GOV-20 Control.\n- The data-lifecycle policies and standards, as the adherence baseline — the Policy items refreshed by the annual review — plus any policy/standards updates or charter amendments this cycle.\n- The charter and membership status, the chartered membership roster, and the quorum rule.\n- The agreement dispositions from the data-sharing and matching review.\n- The standing agenda template and the prior cycle's open action items.\n\n**Procedure**\n_Items 1–5 are agent-run (folded from the former \"Compile data-quality and integrity metrics\" step); the human moment is the council's decisions and the chair's approval of the minutes in items 6–10._\n1. Pull the metric series since the last cycle across the DAMA-DMBOK / ISO 8000 quality dimensions and score each against its threshold: completeness, accuracy, timeliness/currency, consistency, validity/conformity, uniqueness (duplicate rate), and integrity-exception counts (referential breaks, reconciliation failures, unauthorized-change events). Report a rate and a direction, never a bare count.\n2. Compile the data-management oversight summary: adherence to each life-cycle standard, open control exceptions, and remediation status and aging for prior-cycle findings.\n3. Compare each metric to its threshold and to the prior cycle and apply a red/amber/green status. Flag every breach, every adverse trend (e.g., completeness down two consecutive cycles), and every unresolved or aging exception for council attention — each with a proposed owner, not an orphan red cell.\n4. Separate a data-*quality* issue (fix the data or the producing process) from a data-*integrity* issue (a control failure — unauthorized change, broken lineage): the latter is a control finding that routes to remediation, not a cleanup ticket.\n5. Draft the metrics narrative — what moved, why, and what remediation is in progress or proposed — so the dashboard is decision-ready.\n6. Assemble the council packet from the cycle's artifacts — charter and membership status, policy and standards updates, the metrics dashboard and oversight summary, the agreement dispositions — and distribute it to members with enough lead time to read; a packet handed out at the table defeats informed governance.\n7. Convene the council, and a data integrity board session where matching or sharing activity is in scope. Record attendance against the chartered roster and test quorum **before** any vote; a decision taken without quorum is invalid and cannot be minuted as approved.\n8. Work each agenda item to an explicit decision: adopt or defer the policy and charter amendments; accept the metrics with any directed remediation; approve or return each agreement disposition. Capture dissent and abstentions, not only the majority.\n9. Assign an owner and a due date to every action item as it arises — a decision with no owner is not a decision.\n10. Draft the minutes recording attendance and quorum, the discussion, each decision (with the vote where taken), and the action items with owners and dates — the reproducible record COBIT 2019 MEA01 expects of a monitored governance body — and have the chair approve them.\n\n**Record in AssureSwarm**\n- Query the metric feeds (query data); build or refresh the governance dashboard, linked to this step, with per-dimension RAG status against threshold and prior-cycle trend (dashboard create); attach the data-management oversight summary and the metrics narrative (document upload).\n- Create each action item as an Issue item (item create — `issue_type: observation`, `source: management_identified`, `issue_owner`, `target_remediation_date`, `description` citing the minuted decision it traces to), and relate each Issue to the anchor UC-GOV-20 Control (item relationship, Issue ↔ Control).\n- Attach the distributed packet and the chair-approved minutes as the official meeting record (document upload — there is no Meeting item type; the minutes document is the record).\n\n**Exit criteria** — Dashboard current across every in-scope domain and dimension with RAG status versus threshold and prior cycle, every breach, adverse trend, and aging exception flagged with a proposed owner, and quality and integrity issues separated; quorum recorded; every agenda item resolved to a minuted decision; every action item carries an owner and due date; the council chair approves the minutes as the official record.\n\n> **⚡ Audit Artist accelerator:** `/coach-query-data` pulls the metric series across in-scope domains; `/coach-dashboard-create` assembles and refreshes the governance dashboard against thresholds and prior-cycle trend.","label":"Convene council and record minutes","performedBy":{"primitives":["coach-item-create","coach-document-upload","coach-query-data","coach-dashboard-create"]}},"id":"convene-council-and-record-minutes"},{"data":{"description":"Chief Data Officer: Judge action closure evidence and overdue recovery plans, then authorize accurate and appropriately restricted reporting to the chartered audience.","instructions":"**Objective** — Evaluate open and completed council actions and authorize the periodic data-governance report, then retain the complete cycle record and next-cycle commitments.\n\n**Inputs**\n- This cycle's minutes and their action items — the Issue items (issue_type: observation) created at convene-council-and-record-minutes.\n- The open action-item register from prior cycles — open Issue items (issue_type: observation, source: management_identified) linked to the anchor UC-GOV-20 Control.\n- The decision or finding that generated each item, for traceability.\n- This cycle's outputs: charter and membership status, policy and data-lifecycle standard changes, the data-quality and integrity metrics trend, the agreement dispositions, the approved minutes, and the council's decisions and action items with their tracked status.\n- The defined reporting cadence and the recipient list (board, audit or risk committee, executive sponsor), and the prior status report for trend continuity.\n- The records-retention schedule and the governance register.\n- Open action items, deferred agreements, and next-cycle scope notes gathered during the cycle.\n\n**Procedure**\n*Autonomous preparation incorporates Track action items to closure; Chief Data Officer reviews the combined evidence.*\n1. Log each new action item with its owner, due date, and the decision or finding that generated it — traceability back to a council decision is what makes the item auditable.\n2. Pull every open prior-cycle item and refresh its status, closing those completed with evidence attached; a status of \"done\" without evidence is not closed.\n3. Age the open population and flag overdue or at-risk items, linking each to its owner and the council decision it traces to. Watch for chronic carryover — an item slipping three cycles is a governance-effectiveness problem, not a scheduling one.\n4. Draft an escalation note for any materially overdue item, proposing a revised date or an alternative owner, for the CDO or sponsor.\n5. Surface the open and overdue picture so the CDO can confirm coverage before the cycle closes.\n6. Compile the report: charter and membership status; policy and data-lifecycle standard changes adopted; the metrics trend with RAG status; agreement dispositions (approved, returned, or deferred, with each matching agreement's statutory status); and the council's decisions and open action items with owners and dates.\n7. Confirm the report is on the defined interval — the cadence at which data governance must report to executive leadership or the oversight committee (COBIT 2019 EDM05 stakeholder transparency / MEA01; NIST 800-53 program-management governance reporting). Note any lapse and its cause; a missed reporting interval is itself a governance finding.\n8. Tailor the executive summary to the recipient's decision needs — what changed, what is off-threshold, what needs their decision or resourcing — separate from the detailed appendices.\n9. Confirm the distribution list against the charter's reporting obligations and apply least privilege to any sensitive metric or agreement detail (redact where a recipient lacks need-to-know).\n10. Package the report with its supporting evidence for distribution and archival, and have the CDO approve the content and authorize the send.\n11. Confirm the cycle is closable: minutes approved, agreement dispositions recorded (approved, returned-and-resolved, or deferred with an owner), status report distributed, and every open action item owned. A cycle with an unowned open item does not close — it escalates.\n12. Assemble the complete record — the validated (and where applicable amended) charters and membership rosters, the updated policy and standards library, the metrics package, the agreement dispositions, the approved minutes, and this report — and archive it to the retention location with version, approval date, and applicable retention period, linked to the governance register. Verify retrievability by opening the archived copy — an upload confirmation is not proof the record is readable. Any post-archive correction is a new dated addendum, not an edit to the sealed record.\n13. Update linked records so downstream work references this cycle's approved versions: the data governance policy library, the UC-GOV-20 control execution log (cycle period, completion date, result, key metrics), and any workflow that depends on the current charter or policy version.\n14. Seed the next cycle: carry forward open action items, deferred agreements due for re-decision, and scope changes (domains or bodies to add) as owned, dated items for the next cycle's scoping, and flag the next annual charter-and-policy review date so it is not missed.\n15. Confirm the next cycle is scheduled on the standing quarterly cadence; the CDO's approval of the report and the archived record on this step closes the cycle.\n\n**Record in AssureSwarm**\n- Create or update each action-item Issue with `issue_owner`, `target_remediation_date`, and a `description` citing its source decision (item create / item field update), and relate each to the anchor UC-GOV-20 Control (items link, Issue ↔ Control).\n- Close completed items on their Issue (item field update — `actual_remediation_date`, `verified_date`, and status), with closure evidence attached as a document to this step.\n- Track the open items and surface overdue and at-risk status (workflow monitor); send the escalation notes for materially overdue items (notify).\n- Export this cycle's items into the report package (item export) and refresh the reporting dashboard linked to this step (dashboard create); render the status report package (render package) and distribute it to the recipient list at the reporting interval (notify).\n- Export the workflow instance as the archive package (workflow export) — the archived instance is the durable governance record — and relate it to the anchor UC-GOV-20 Control (item relationship).\n- Record the control execution-log entry (cycle period, completion date, result, key metrics) and the next-cycle schedule on this step (step note — the Control has no native execution-log field).\n- Confirm the refreshed Policy items (policies, standards, and charter Policy items) now carry this cycle's approved `version` and `next_review_date` so downstream work references the current baseline (item field update); link the archived record to the governance register (document link).\n\n**Exit criteria**\nJudge action closure evidence and overdue recovery plans, then authorize accurate and appropriately restricted reporting to the chartered audience.\nEvery open action item, this cycle and prior, has a named owner and a closure record or a credible plan with a date; completed items are closed with evidence; overdue items are escalated; the CDO confirms coverage before close.\n\n\nReport compiled and reconciled to the cycle's records; reporting interval met or the lapse noted with cause; the distribution list matches the charter's reporting obligations; the archived record is verified retrievable and durable enough to serve as evidence without oral explanation (charters, membership, policies, metrics, agreement approvals, minutes, report); the control execution log is updated; every open thread is carried forward with an owner and date; the next cycle is scheduled and the annual-review date flagged; the CDO approves content and distribution, authorizes the send, and that approval closes the governance cycle.\n\n> **⚡ Audit Artist accelerator:** `/coach-render-package` renders the status report with its evidence appendices; `/coach-notify` distributes it to the oversight committee at the defined reporting interval with a logged send trail.","label":"Report data governance status","performedBy":{"primitives":["coach-item-create","coach-items-link","coach-workflow-scan","coach-notify","coach-dashboard-create","coach-export-package","coach-render-package","coach-workflow-export","coach-document-upload"]}},"id":"report-data-governance-status"}],"sourceTemplateId":"workflow-library:grc-data-governance-council-operations"}
