Governance Starter Pack
Rodan · First 30 days · guides.rodan.io
Rodan · Resources · Governance
Governance Starter Pack
A condensed start: systems register fields, classification levels and the first thirty days of action. Enough to begin without boiling the ocean.
Principles for week one
- CFO or equivalent owns governance at mid-market. IT enables.
- Include spreadsheets, pixels and shadow systems in the register.
- Classification drives access. Do not invent a fifth level on day one.
- Perfect is the enemy. A living 80% register beats a perfect one that never ships.
Systems register template fields
Copy these twenty columns into a sheet. One row per system (including material spreadsheets).
| # | Field | Notes |
|---|---|---|
| 1 | System name | Human-readable, unique |
| 2 | Vendor / hosting location | SaaS vendor or self-host region |
| 3 | Business owner | Named person, not a team alias |
| 4 | Purpose | Why the system exists |
| 5 | Data categories | Customer, finance, HR, product, etc. |
| 6 | Personal data flag | Yes / No |
| 7 | Special category flag | Yes / No |
| 8 | Classification | Public / Internal / Confidential / Restricted |
| 9 | Lawful basis | If personal data |
| 10 | Volume (approx) | Records or scale band |
| 11 | Source | Where data enters from |
| 12 | Flows to | Downstream systems |
| 13 | Access controls | SSO, MFA, role model |
| 14 | DPA status | Signed / missing / N/A |
| 15 | Transfer mechanism | If outside UK / EEA |
| 16 | Retention rule | Policy or “unknown” |
| 17 | Backup / recovery | Tested? RTO note |
| 18 | Criticality | Trading / reporting / low |
| 19 | Contract renewal | Date or N/A |
| 20 | Notes / risks | Open issues |
Classification levels
| Level | Definition | Examples |
|---|---|---|
| Public | No harm if disclosed | Published marketing, public price lists |
| Internal | Minor harm | Process docs, org charts |
| Confidential | Material harm | Customer lists, financials, contracts |
| Restricted | Severe harm | Special category data, payment data, M&A material |
Access, sharing and AI connections follow the highest classification of data in the system.
First 30-day actions
Days 1–7
- Name a governance lead and a fortnightly 30-minute forum
- Draft the register sheet with the twenty columns above
- List the top 15 systems by criticality (include finance, CRM, warehouse, storefront, HR)
- Agree the four classification levels with leadership in one page
Days 8–14
- Complete register rows for the top 15 (owners, personal data, DPA status)
- Flag shared admin logins and missing MFA on Confidential / Restricted systems
- Identify the three metrics that cause the most board argument; note source systems
Days 15–21
- Classify every row in the top 15
- Chase missing DPAs for processors that touch personal data
- Write a one-page retention default for customer and prospect records
Days 22–30
- Close or schedule the top five access and DPA gaps
- Publish the register location and review cadence (twice a year minimum)
- Run the governance self-assessment and keep the score for the next forum
- Park AI / new analytics work that would touch unclassified personal data
What not to do in month one
- Do not buy a governance platform before the register exists
- Do not write a 40-page policy nobody will read
- Do not invent custom classification labels
- Do not connect an LLM to Shopify, CRM or HR until classification and DPAs are honest

