Skip to content

Governance Mining — what is analysed and what is not

This page is written for works councils, data protection officers and tenant admins. It explains the commitments Governance Mining keeps — and states explicitly what the platform does not do.

The binding version is in the application, not here. Under Governance Mining → Scope of analysis the platform generates a processing description from your tenant’s actual configuration — with version and date. If an admin enables something, that document changes. This help page explains the rules; the values in force are there. That way no number in the documentation can diverge from the number in the software.

Every statement Governance Mining makes concerns a role, a value stream, a relationship — never a person. Even self-approval, which by its nature involves people, is counted per object: “two changes to this value stream were approved by the person who submitted them”. The evidence names the change and the date, not a name.

The reason the approval process holds people at all is the traceability of decisions — which is precisely why no personal metrics are derived from it.

Linking a user account to a person is voluntary. Without it, the platform cannot establish a self-approval — and says exactly that. It does not say “there are none”. This distinction is deliberate: a reassurance based on missing data would be a false assurance.

The same principle applies everywhere: whatever could not be evaluated appears as a hold with reason and count — never as “nothing found”.

Every number, every severity and every ranking is derived deterministically from the model. The assistant may explain and phrase findings; it does not determine severity, thresholds or order. Nor does it get access to actors or case identifiers.

This list is part of the product. It also appears in the Scope of analysis inside the application, so that it reads as verifiable configuration rather than a marketing claim.

  • No ranking of people — in no view, not even as a sortable column.
  • No cycle times for individuals. Instead of “person X takes 4 days on average” there is “these drafts have been open for more than X days” — same benefit, no personal assessment.
  • No read events. Who looked at what is not collected. This gap stays open deliberately.
  • No presence, attendance or working-time patterns.
  • No content and no titles of messages, meetings or documents.
  • No productivity metrics from source code systems.
  • No personal case types — recruitment, health, disciplinary proceedings and whistleblowing/grievance procedures are blocked as a source, not merely off by default. The difference matters: a default could be changed. The block already applies in the Suitability check — is my case log fit for a process analysis? — if such a case type is declared, the sample is not even evaluated.
  • No metric below the minimum group size. The cell stays empty; even the note about it names no number one could back-calculate from.

Person-level analysis: a separate contractual item

Section titled “Person-level analysis: a separate contractual item”

Analysis involving personal data is not part of Governance Mining. It is a separate opt-in (Person-level analysis) that your tenant’s tenant admin must switch on explicitly — it touches works-council co-determination, so you decide, not roleALPHA. As long as it is off, the affected endpoints return the aggregated form — not an error and not the raw form. That way it cannot be switched on by accident. If roleALPHA switches it on on your behalf, this is logged with a reason.

Whether it is switched on for your tenant is stated in the Scope of analysis.

Three different things with three different periods — the values in force are in the Scope of analysis:

WhatRule
FindingsResolved and decided findings expire after the configured period. An open finding does not expire: it describes a current state, and expiry would be silent forgetting.
Change history (commit log)Approval metadata: who, when, under which mode, with what reason. No field values.
Change logThe field values of a change live with the respective data node and expire there. After expiry the history still shows that something changed, no longer what.

Analyses that may touch employees’ conduct or performance are subject in Austria to §§ 96, 96a ArbVG and regularly to a data protection impact assessment under Art. 35 GDPR. That obligation sits with the customer as controller; roleALPHA is a processor. The processing description in the Scope of analysis exists to make exactly this assessment possible — it is citable because it carries version and date and is generated from the real configuration.

Related: Governance Mining · What does this hold about me? · Suitability check — is my case log fit for a process analysis? · Org Intelligence · Change history