Governance Mining
roleALPHA describes how your organisation is supposed to work: roles, value streams, responsibilities, relationships. Governance Mining answers the second half of the question — whether the model is internally consistent and whether it matches reality. It finds contradictions, gaps and irregularities, backs every statement with evidence, and offers exactly one action for each.
You reach the page under Settings → Data & Structure → Governance Mining
(/governance). It is not restricted to administrators: findings are the work of
value stream and role owners. Which findings you see is decided by your visibility — you
will not learn about an object you are not allowed to see through a finding either.
The three tabs
Section titled “The three tabs”| Tab | Answers | For whom |
|---|---|---|
| Findings | “What is open in my area?” | Value stream and role owners |
| Scope of analysis | “What is analysed here at all — and what explicitly is not?” | Tenant admins, works councils, data protection officers |
| Approval process | “How does our own approval process actually run?” | Tenant admins, value stream owners |
| My data | “What does this hold about me?” | Every employee |
What this stage finds
Section titled “What this stage finds”Five analyses, all deterministic — they establish facts, they do not guess. None needs an external data source, none changes your model.
| Finding | What it means |
|---|---|
| Generic relationship type despite a specific one | A link uses a type without constraints although a purpose-built one exists for this pair. The generic type is an escape hatch, not a choice — and it blurs every analysis that runs over that edge. |
| Cycle | A decomposition or ordering runs in a circle: “A is part of B is part of A”. That is a contradiction — the hierarchy cannot be rendered and the sequence cannot start. |
| Multiple parents | An element sits under several parents. The hierarchy view shows only one of them, and which one is decided by the order of the links. A silent loss of information. |
| Not connected | An object has no link at all, or an entire group hangs off nothing in the rest of the model. Such objects appear in no analysis that runs over relationships. |
| Self-approval | Whoever submitted a change approved it themselves. The first statement the platform can make about its own approval process. |
Unassociated library templates are excluded — they are deliberately unlinked, so a finding about them would always be wrong.
One finding, three decisions
Section titled “One finding, three decisions”There are exactly three ways forward for every finding — and none in which it simply disappears:
- Acknowledge — you have seen it and are working on it. It stays in the list.
- Accept for a period — the deviation is intentional. A deadline is mandatory; there is no open-ended acceptance. Once it expires, the finding is open again.
- Reject — the finding is wrong. A reason is mandatory. A rejected finding does not come back, even if the next run finds it again.
Resolved cannot be set. A finding counts as resolved when a complete run no longer finds it — otherwise the list would only be short because someone tidied up.
Why an empty list proves nothing
Section titled “Why an empty list proves nothing”The most important thing on this page sits above the list: the state of the last run, and what it could not evaluate.
- If no run has happened yet, the page says so explicitly. The empty list below is not a result.
- If the run was incomplete — a module unreachable, a list truncated, a value missing — that appears as a hold underneath, with reason and count. A finding is then not resolved: the run did not look everywhere.
- Only after a complete run with no holds does “no findings” actually mean “nothing found”.
What gets grouped — and why
Section titled “What gets grouped — and why”Some irregularities occur a hundred times over. They are then reported as one statement with a count, not as a hundred rows: “29 links use a generic type although a specific one exists” is one finding, not 29. Likewise, objects with no link at all are grouped per module.
That has a consequence worth knowing: when a 30th link of the same kind appears, it is the same finding with a higher number — it is not new, and the previous one is not resolved. Your decision about it stands.
A finding names at most 50 objects explicitly; the full count sits next to it. If an analysis finds more than 50 individual findings, it is truncated — and the truncation appears as a hold, so the list does not look complete.
Your own approval process
Section titled “Your own approval process”Under Approval process you find metrics about the platform itself: how long a change takes from submission to approval (median and p90 — an average alone hides the bad case), how many decisions are waiting and since when, how often a change landed with fewer approvals than its mode requires, and where changes come from (person, connector, automation).
The assistant is missing from this breakdown — and that is stated here rather than counted in silently. What you create through rALPH is made under your own login; at approval time it cannot currently be told apart from a hand-made change, so it counts as person. An “assistant” share would always read zero, and that would be precisely the wrong number. While this holds, the breakdown says something about connectors and automations — not about how much the assistant contributes.
None of these numbers names a person. There is no per-person cycle time and no ranking of approvers — not even as a sortable column. Instead of “person X takes four days on average” the platform says “these drafts have been open for more than three days”: the same benefit for the organisation, without performance assessment.
Every number carries its basis. Cycle time needs the moment the draft was created — that sits on the draft, and drafts expire after their retention period. For older changes it is therefore not measurable, and that is what it says, rather than forming a nicer number from what remains. Likewise an approval mode the platform does not recognise is reported as not assessed rather than counted as fine.
The governance index
Section titled “The governance index”Above the findings list sits a number from 0 to 100 — and never on its own. Below it stands
every component it is built from: with its ratio, the raw values (71/100) and the share with
which it enters the total.
There is a reason for that. An overall score without a breakdown can be put into a presentation and used in a performance review, and it then gets optimised instead of understood: you lift the cheapest component, and the organisation does not change.
What the number means — and what it does not
Section titled “What the number means — and what it does not”| Rule | Why |
|---|---|
| Every component is a ratio, not a count | “12 value streams without an owner” is a catastrophe with 15 value streams and a rounding error with 3,000. |
| A component without data does not lower the number | It is excluded and the weights spread over the remaining ones. Otherwise every tenant that does not subscribe to a module would be punished. |
| Implausible numbers are excluded, not clamped | Clamped, a broken measurement would look like a perfect result. |
| From too few components the number is not an overall statement | And the card says so explicitly. An overall score from one component is that component. |
| Without a run there is no number, not a 0 | A 0 would be the statement “everything is broken”. There is simply no basis. |
The weights
Section titled “The weights”They are a product decision and live in one place in the code, so that changing them stays a deliberate act — it shifts the statement for all tenants at once.
| Component | Weight | Rationale |
|---|---|---|
| Value streams with an owner | heavy | A value stream without an owner is the most expensive modelling error: nobody decides about it. |
| Changes with sufficient approval | heavy | Here a commitment towards third parties is broken, not just a model blurred. |
| Roles someone holds | medium | An unfilled role is often a known state. |
| Relationships with a fitting type | light | Does not make the organisation unable to act, only unreadable. |
| Elements that are connected | light | A standalone element often stands alone on purpose. |
Two components (value stream ownership, role occupancy) only come into being in a later stage. Until then they appear as not included with that note on the card — they do not lower the number.
Trends
Section titled “Trends”Metrics can be evaluated as a trend. The basis is the snapshot every report run records anyway — no additional collection is needed.
Three things apply:
- Monthly values by default. That is not a presentation choice: the raw data behind some metrics expires after 90 days, so a trend over twelve months may only consist of previously compacted monthly values. The monthly value is the median of that month’s measurements — a single failed measurement should not leave permanent traces.
- A missing measurement is not a 0. It drops out of the trend instead of pulling it down. Otherwise a failure of the measurement would look like a collapse of the organisation.
- Notable points are determined against the past only. A point is compared with the measurements before it, never with later ones. Otherwise a change would be dated to a day on which it was not yet detectable — and “since April” would be wrong.
What there is not: a forecast. No line is extended into the future, because there is no basis for that in this product.
Where findings also appear
Section titled “Where findings also appear”On every object’s detail page, in the Reports tab, a card shows the findings for that object — as counts per analysis and severity. The evidence deliberately stays on the Governance page only: it can name other objects, and there the visibility check applies to each one individually.
Ranking
Section titled “Ranking”The list is sorted by impact, not by time: severity × confidence × affected objects (the last logarithmically, so a finding covering 100 objects does not displace ten more important ones). This calculation is arithmetic — no language model determines order, severity or number.
Which sources are connected
Section titled “Which sources are connected”The Analysis scope tab states first which external systems are connected — per source its name, whether it is enabled, when it last collected, and what it captures and what it does not. That is the first question any works council asks, and it is answered from the live configuration rather than from a leaflet.
Credentials, addresses and directory paths are deliberately absent. The document gets passed on; an endpoint in it would be a disclosure to anyone who receives it. For the question “which systems are connected”, the type is enough.
Three states must be distinguished, and the card does so explicitly:
| Display | Meaning |
|---|---|
| a list | exactly these sources are configured. A disabled source stays listed — it does not collect, but it is set up |
| “no external source connected” | a real statement: the analysis runs solely on data the platform holds itself |
| “cannot be determined” | the interaction-signals data node is not switched on or currently unreachable. Expressly not a statement that no source is connected |
Entering and changing sources happens not here but under Settings → Data & structure → Org Intelligence — that is where the collector type, the credentials and the switch live. How to do it is in Configure Data Sources; the prerequisites (admin role and the Org Intelligence data node switched on) in Org Intelligence. The analysis scope is a document, not a control panel — otherwise there would be two places to configure the same thing.
Volumes, cost and limits
Section titled “Volumes, cost and limits”Analyses cost compute time, ingesting external events costs storage, and the AI layer costs real money at a provider. So that none of this becomes a surprise, there are three quotas and a cost estimate before the first run. Both live in the Analysis scope tab.
| Item | What it limits |
|---|---|
| Ingested events per month | what comes in from external sources — the only volume that a change at a source can multiply a hundredfold overnight |
| Compute minutes per month | what is computed from it. A full run across a tenant with 2,000 employees is minutes, not milliseconds |
| AI budget per month | what the language model reads of it. Kept in euro cents, not tokens: a limit in tokens would be a different promise after the next model change. Only usage via the platform’s key counts — with your own AI key (Your own AI keys) usage stays at €0. Providers charge in US dollars; conversion uses the daily reference rate of the European Central Bank |
At the limit the request is refused, not throttled. That is deliberate. A throttled run is slow and still expensive, the bill keeps rising, and nobody learns that a limit was reached. A refusal is a statement you can act on — it names the limit, the usage and what remains.
Usage is measured at the moment of the check — events, compute minutes and AI cost of the current calendar month, not yesterday’s figure. A new tenant can start right away, and whoever reaches their limit learns it on the next run rather than the next day.
If usage cannot be measured, the quota counts as exhausted. The refusal then says explicitly that the measurement is missing, not the quota — otherwise you would go looking for usage you do not have. This is not obstruction but an asymmetry: an unnecessary refusal costs a click, an unnoticed overrun costs money nobody agreed to.
Who sets the limits. The level of each quota and the threshold from which you are warned (default: 80 %) are set by your tenant admin — up to an upper bound that roleALPHA sets for your tenant. Without a choice of your own, the defaults apply. A limit above the upper bound is refused, with the upper bound in the message; roleALPHA agrees a higher upper bound with you. If roleALPHA lowers the upper bound below your choice, your choice is lowered to the new upper bound, and the log names both values. If roleALPHA changes your choice on your behalf, it is logged with a reason.
Plus a minimum gap of 15 minutes between two runs — even with quota to spare. Findings do not change by the second; twenty runs in a row would be twenty bills for the same result. The tab shows when the next one is possible.
rALPH and the findings
Section titled “rALPH and the findings”You can ask the assistant about the findings — “what is unusual about our approval value stream?” — and get an answer built from evidenced findings, not from the model’s guess. What applies:
What rALPH can do:
| Give an overview | counts per analysis and severity with a few high-impact examples. Never the raw list — it would be silently truncated before the model, and half a list would look like a whole one. If anything was left out, that is stated explicitly. |
| Explain one finding | what was found, why, on which evidence, what can be done — and what the finding does not say. The explanation is derived from the stored fields, not invented prose. |
| Turn it into a proposal | for the few findings with a mechanically unambiguous fix, a draft is created. Nothing changes until it is approved. For all others rALPH refuses and states the reason — instead of inventing a link. |
| Decide a finding | accept with an expiry date, or reject with a reason. These are real writes and are blocked in ask mode. |
What rALPH cannot do: create a finding, set a severity, compute a number or determine a ranking. All of that arises deterministically in the analysis run. The model reads and phrases.
And one distinction that matters: if the analysis service is not released for AI, rALPH says so explicitly — “not released for this tenant”. Not “no findings”. The difference is between “we have a problem” and “we have none”, and it must not disappear into an empty list.
Every AI call is logged with provider, model, tokens and cost (Your own AI keys), and every draft created by rALPH carries the origin “assistant” — so the approval-value stream tab shows how much of the model now comes from the assistant, and how much of that was rejected.
What this page does not do
Section titled “What this page does not do”- It changes nothing. Every adoption runs through the usual draft with approval.
- It does not evaluate people. See Governance Mining — what is analysed and what is not.
- For a cycle it proposes no link to delete. Any of the links involved would break the circle; which one is wrong only a human knows. The finding gives you the chain and the links involved.
And it is not process mining. The difference is not precision but subject: value stream analysis assesses the case — an order, an invoice, a ticket — and optimises cycle times. Governance mining assesses accountability. Expressly not included:
- no control-flow conformance on business processes (no token replay, no alignments, no fitness/precision) — “conformance” here means sequence, actor, rule
- no BPMN and no XES import
- no desktop capture, no read events, no working-time patterns
- no connector library for ERP systems
- no statement about the cycle times of business processes
If you want to know why a case takes long, you need a process analysis tool. Terms in the Glossary; whether a case log holds up at all is what the Suitability check — is my case log fit for a process analysis? says.
Related: Governance Mining — what is analysed and what is not · What does this hold about me? · Validator · Change history · Approval Modes · Understanding Relationships · When two people work at once