What Is the Governance Framework?

The DCPF Governance Framework establishes the authority, boundaries, standards, review expectations, and controls that guide sustained human-AI work. It helps people state how work should be performed, what the AI may and may not do, how information and outputs will be evaluated, and who has authority to approve important decisions.

Governance is an architectural responsibility, not simply a document or a final inspection. Its controls operate wherever they are needed: inside Research Requests, Knowledge practices, Runtime Requests, human reviews, and recurring project procedures.

Governance makes the human-authorized operating conditions of the collaboration explicit.

DCPF is experimental.

DCPF has demonstrated promise through development work, practical applications, and training practicums, but it has not been broadly or independently validated across domains, organizations, AI systems, or production environments. Begin in a controlled, low-risk setting, validate the Governance controls needed for your own domain and environment, and retain human judgment, verification, and accountability throughout the work.

Read the Copyright & Important Notice

Governance Operates Across DCPF

Governance is not a one-time first step and does not sit at the end of the workflow. People use Governance responsibilities while defining and building the artifact needed for the work. Applicable controls are placed directly in that artifact so they are present where the AI and human reviewers need them.

  • In Research, Governance can control acceptable sources, evidence quality, scope, prohibited methods, uncertainty reporting, and review requirements.
  • In Knowledge, Governance can control what may become Accepted Knowledge, who may approve it, how status is represented, and when it must be reviewed or retired.
  • In Runtime, Governance can control execution boundaries, required inputs, prohibited actions, output standards, stopping conditions, and human approval points.
  • In human review, Governance can define who decides, which criteria apply, what must be documented, and what happens when requirements are not met.
The Governance Framework guides. Building artifacts reveals additional Governance controls. The Governance Repository preserves recurring Governance.

The Seven Standard Governance Responsibilities

Every DCPF implementation should address seven standard Governance responsibilities. Their form and depth should be proportionate to the work. A low-risk personal project may answer them briefly, while consequential or regulated work may require formal policies, records, approvals, and domain-specific controls.

1. Purpose and Scope

Define why the work exists, what it includes, what it excludes, and the conditions under which its results may be used.

Teaching question: What is this work authorized to accomplish, and where does that authorization stop?

2. Human Authority and Decision Rights

Identify who may direct the work, approve important changes, accept evidence or Knowledge, authorize use, and resolve disagreements or exceptions.

Teaching question: Which decisions belong to people, and who is authorized to make each one?

3. Standards and Success Criteria

State the quality, accuracy, completeness, accessibility, style, performance, or domain standards that the work and its outputs must satisfy.

Teaching question: What does acceptable work look like, and how will reviewers recognize it?

4. Boundaries and Prohibited Actions

Define legal, ethical, safety, privacy, operational, technical, and project-specific limits, including actions the AI must not take.

Teaching question: What must the system avoid, stop for, or return to a human?

5. Evidence and Information Controls

Establish expectations for sources, provenance, recency, uncertainty, conflicts, confidentiality, and the distinction between evidence, accepted information, and generated content.

Teaching question: What information may the project rely upon, and what proof or qualification must accompany it?

6. Review, Validation, and Acceptance

Define required human reviews, validation methods, acceptance criteria, escalation paths, and the decisions available when work does not meet requirements.

Teaching question: Who must review this work, against what criteria, before it can be accepted or used?

7. Change, Version, and Maintenance Control

Define how recurring controls are recorded, approved, versioned, communicated, reviewed, replaced, and retired as the project changes.

Teaching question: How will the project know which Governance is current and how an authorized change becomes effective?

The Governance Framework and Governance Repository Are Different

The Governance Framework is the architectural responsibility for defining and applying Governance. The Governance Repository is the maintained project home for recurring Governance controls that should persist across artifacts, tasks, or executions.

Beginners do not need to complete a separate Governance Repository before useful work can begin. Start by applying the seven responsibilities while building the relevant Research, Knowledge, Runtime, or review artifact. State needed controls inside that artifact. When a control becomes recurring, shared, or important to maintain independently, preserve it in the Governance Repository.

This iterative approach allows the work to reveal the Governance it actually needs while keeping applicable controls inside the artifact before execution.

When a Governance Responsibility Is Left Undefined

An undefined responsibility does not disappear. Its decisions are pushed into the moment of execution, where they may be assumed inconsistently by a user, an AI model, a tool, or an unexamined default. This can produce scope drift, uneven source selection, unsupported claims, accidental disclosure, inconsistent approvals, unreliable outputs, or confident AI-generated assumptions sometimes described as hallucinations.

The purpose of Governance is not to eliminate every risk. It is to make authority, boundaries, standards, and review conditions visible enough that people can identify omissions, assign responsibility, and decide whether the remaining risk is acceptable.

A Practical Way to Begin

  1. Define the work and the intended use of its results.
  2. Choose the Research, Knowledge, Runtime, or review artifact needed next.
  3. Use the seven Governance responsibilities to identify the controls that artifact needs.
  4. Place those controls directly in the artifact before giving it to the AI.
  5. Execute the artifact and perform the required human review.
  6. Preserve recurring or cross-project controls in the Governance Repository.
  7. Update the applicable artifact and Governance Repository when experience reveals a gap or needed change.
Use enough Governance to make the work controlled and reviewable, then expand it when the risk, scale, or domain requires more.

Where to Go Next

Governance supplies the operating conditions for the rest of DCPF. The next pages explain how those conditions shape Research, the preservation of Accepted Knowledge, and Runtime execution.