Role Playbook · 2026

Data Governance Lead

Policy and lineage without quarterly scrambles. Auto-discover ownership, classify sensitive columns, and export audit-ready graphs on demand.

22 min read Runbooks Metadata only Apache 2.0

Executive summary

Deploy Metroflow as your living governance graph. Auto-tag PII-adjacent assets, export SOC2/GDPR lineage in hours, and run impact analysis before policy changes.

Static diagrams go stale the week you publish them. Metroflow discovers ownership and sensitive columns from live pipelines. Governance stays current without quarterly scrambles.

AlwaysCurrent graph tied to production
HoursAudit exports vs months of manual tracing
100%PII tables with downstream consumer map
01

What broken lineage costs you

Typical patterns for Data Governance Lead teams. Ranges, not guarantees.

SOC2 auditor request

Weeks of manual lineage tracing

With Metroflow: On-demand export from live graph.

PII in unknown dashboard

Compliance incident

With Metroflow: "List all consumers of tables with email columns."

Ownership stale

Nobody accountable for assets

With Metroflow: Auto-discovered owners from pipeline metadata.

Policy change untested

Breaks downstream consumers

With Metroflow: Impact analysis before rollout.

Metadata only. Metroflow crawls schemas, job names, manifests, and dashboard definitions. Your production data rows never leave your network.

02

Your stack, one graph

Metroflow sits above the data path, not inside it. One searchable map for your entire role.

Governance sits on metadata: who owns each table, which columns are sensitive, and every downstream consumer: from warehouse to BI to ML features.

03

Where are you today?

Most teams land at L1 or L2. Target L4 in 90 days.

L1Siloed docsWikis and spreadsheets disconnected from production.
L2Partial lineageSome tool lineage exists. Cross-layer gaps remain.
L3Unified graphOrchestration, warehouse, and BI in one map.
L4Certified metricsKPIs owned, enforced, and traced end-to-end.
L5Proactive opsPre-merge gates. Stale assets caught early.

Quick self-check

  • Answer "what breaks if X fails?" in under 15 minutes?
  • Cross-functional teams share one definition of core KPIs?
  • Incidents include downstream dashboard impact without Slack archaeology?
  • Changes include cross-layer impact checks before merge?
  • Named owners for certified metrics and critical pipelines?

0–2: Start Week 1 connect · 3–4: Certify metrics · 5: Add change gates

04

Choose your path

Every org is different. Pick the track closest to your context.

SOC2-focused SaaS

Access controls, change management, lineage evidence

Priority: Export first: critical system lineage pack

GDPR / privacy-heavy

PII tagging, retention, right-to-erasure impact

Priority: Map first: email/PII column consumers

Regulated industry

HIPAA, PCI, model risk overlays

Priority: Map first: sensitive data flows and ML features

05

Who owns what

Assign decision rights up front. Metric fights are governance problems.

RoleOwnsOn Metroflow
Governance leadPolicies, audits, classificationOwn living graph. Audit exports. Policy impact tests.
Security / legalCompliance frameworksReview exports. Approve metadata-only crawl.
Data platformPipeline metadataEnsure crawlers cover all systems.
Domain ownersAsset ownership accuracyValidate auto-discovered owners quarterly.
06

30 · 60 · 90 day rollout

A program with gates, not just a connector checklist.

Days 1–30

Discover & classify

  • Crawl warehouse, dbt, BI, orchestration
  • Auto-tag PII-adjacent columns
  • First ownership review
Gate: 90% prod tables have owner candidate
Days 31–60

Audit readiness

  • SOC2 lineage export template
  • PII consumer map
  • Access audit log integration
Gate: First audit export in < 1 day
Days 61–90

Policy ops

  • Impact analysis before policy changes
  • Quarterly governance review cadence
  • Zero stale static diagrams
Gate: Audit cycle time cut 50%
07

Incident runbook

When pii_consumer_audit is in trouble. Follow this timeline.

T+0 · Request
Auditor asks
"Prove who can see customer email data."
T+15 min · Query
PII consumer map
"List all downstream consumers of tables with email columns."
T+45 min · Export
Lineage pack

SOC2-ready export with owners and BI consumers.

T+2h · Review
Legal sign-off

Validate against access policies.

T+24h · Deliver
Auditor package

Living graph evidence, not stale slides.

Slack template

[GOVERNANCE] SOC2 lineage request: delivered Scope: customer PII tables + all downstream BI/ML consumers Export: 47 assets mapped · 12 BI explores flagged for review Owner: @governance-lead · Legal reviewed Metroflow export: [paste link]
08

Metric certification pack

Copy into your governance doc. One definition. One owner. Full lineage.

Governance coverage

Track first
Formula
% production assets with owner + classification in Metroflow.
Target
95% by day 90.
Owner
Governance Lead

PII consumer mapping

Track second
Formula
% PII-adjacent tables with complete downstream consumer list.
Target
100% for tier-1 PII.
Owner
Governance + Security
09

Daily workflows

Four situations you will hit every week.

📋

SOC2 / audit request

  1. Scope assets

    Systems in audit boundary.

  2. Export lineage

    One-click pack.

  3. Legal review

    Deliver to auditors.

🔒

PII discovery

  1. Auto-tag

    Email, phone, SSN patterns.

  2. Consumer map

    BI, ML, exports.

  3. Remediate

    Unauthorized consumers.

⚖️

Before policy change

  1. Impact query

    Who breaks if we restrict X?

  2. Notify owners

    Downstream contacts.

  3. Rollout plan

    Phased with verification.

📅

Quarterly governance review

  1. Ownership accuracy

    Validate with domain leads.

  2. Stale policies

    Retire outdated diagrams.

  3. Coverage score

    Report to Head of Data.

10

Copy-paste queries

Company Brain or lineage search. Context included.

PII
"List all downstream consumers of tables with email columns."
SOC2
"Export lineage for all assets in the SOC2 audit boundary."
Ownership
"Which production tables have no owner in Metroflow?"
Policy impact
"What breaks if we restrict access to dim_customers?"
Access
"Show audit log of who queried sensitive assets last 30 days."
GDPR
"Map all systems that process EU customer PII."
11

Glossary

Plain English. "Why it matters" tells you when to care.

PII
Personally identifiable information.
Why: Must map every downstream consumer.
Classification
Sensitivity label on columns and tables.
Why: Auto-discovered from schemas.
Lineage export
Audit-ready graph snapshot.
Why: Replaces manual diagram projects.
Ownership
Accountable team for an asset.
Why: Auto-discovered, validated quarterly.
Policy impact
Downstream effect of access/rule changes.
Why: Run before enforcing new policies.
Metadata only
Crawls schemas and jobs, not row data.
Why: Security approves faster than ETL tools.
12

Outcomes checklist

Measure if the program is working.

Success metric90-day target
Audit lineage export timeHours vs months
PII tables with consumer map100% tier-1
Production assets with owner≥ 95%
Static governance diagrams in useZero

Ready to put this playbook to work?

Week 1: connect your stack and run your first blast-radius query. Week 4: certify your first KPI. Week 8: operationalize the runbook.