Data Governance Checker
Roster name: datagov. See also Data governance.
What it does
Every day it checks each connected data source for an owner, safe credentials, encrypted transport, data quality and personal-data exposure, without reading a single row.
What it reads
- The tenant’s connection registry.
- The structure and counts that Resolve’s Explore recorded: tables, columns, types, null counts and keys. Never values.
What it produces
Per connection, a result for each control: pass, warn, fail, or unable to assess (with the reason):
- a missing owner or environment;
- credentials kept inside the address;
- unencrypted transport;
- columns declared not-null that contain nulls (fail);
- tables without primary keys (warn);
- columns that look like personal data (email, phone, national ID) and are unmasked (warn), and such a dataset readable by more than ten distinct principals (warn);
- freshness, which is always reported as unable to assess, because no refresh cadence is declared.
The findings go to the living “Data governance status” issue and the console’s findings store. A source nobody explored is reported unassessable, with the reason.
Human oversight
A person assigns owners, rotates credentials and adds masks. The checker changes nothing.
Model
None. Every finding is computed by rules. This agent calls no model.
Where it runs and data handling
On your Runink TIDE deployment. It holds no credential and dials no data source: it reads only what Explore already recorded. No row or cell value is read.
Guardrails
- No model and no values: findings are rule outputs over structure and counts.
- Unassessable is never a pass.
- A verdict per control, per source, rather than a blended score.
Limitations
- A source nobody explored stays unassessable.
- Its personal-data findings are a starting point for review, not a guarantee that every sensitive column was found.
- It reflects the structure as of the last Explore.
Evaluation
No published evaluation scores yet.
Illustrative example
Invented connection. A Postgres connection has no owner, and its address contains a password. Explore recorded an email column, unmasked and readable by fourteen principals. Findings: ownership fail, credential in address fail, personal-data exposure warn, access breadth warn. Transport uses TLS: pass.