Governance
Review & overrides

The operating model is simple to state: the system authors, the operator reviews. Nobody hand-edits data. Configuration takes effect when authored and every piece of it is reviewable, revisable, and attributable after the fact — which is a stronger control than an approval click, because the record shows what was decided and why, not just who pressed the button.
The review surfaces
- Pending queues — everything below the confirmation bar waits for a person, with evidence attached.
- Identity conflicts and unclassifiable records, routed with the reason stated.
- Stakeholder review — the service model is reviewed against a pre-built, evidence-backed draft in minutes, not authored from a blank page in workshops.
Overrides are first-class
An operator override is not an edit — it is a recorded decision that takes precedence over automated results, survives re-runs, and stays attributable. Overrides never disappear into the data; they remain visible as the human judgment they are.
Review feeds the engine
Every confirm and reject an operator makes becomes a calibration label, held in your environment. The matching engine's release gate runs against those labels — your review work directly hardens the bar the engine must clear.
Design Principle
Automation does the authoring; people do the judging; the record keeps both honest. Nobody's job is retyping data.
All docs