Analytical Governance
Producing a result is not the same as serving an answer.
Analytical Governance is the discipline governing the legitimacy of the analytical service: the user’s purpose must survive the passage from expressed intent to an answer, the result must be established under the analytical law and support that apply, and the answer must carry no more authority than its grounds warrant.
Conformance test
A conforming analytical service must be able to withhold or qualify analytical permission. Refusal is not an error state; it is the evidence that the permission is real.
Analytical Governance: Governing the Legitimacy of the Analytical Service The category paper. This page is a doorway; the deposit governs.
A number the database can produce and the service cannot yet serve
What was average revenue per open store yesterday?
- 47 revenue rows arrived
- what reported — not what was open
- the sales table
- 50 stores exist
- the roster — not that 50 were open
- the store roster
- 48 were open yesterday
- the requested population
- the operating-status source
The arithmetic can divide total observed revenue by 47, by 48, or by 50. Take the first one. It may be arithmetically correct. The query may execute exactly as specified. The value may be reproducible. The derivation may be lawful for that narrowly defined analytical object — the mean of observed revenue over the stores that reported.
None of those facts establishes that the value is the answer to the question that was asked. Correctness is always correctness with respect to something, and the something here is a narrower object than average revenue per open store. The computation does not tell us which answer serves the user’s purpose.
The 50-store roster does not establish that all 50 were open. The 47 revenue rows do not establish the open-store population. A system that serves the mean over reporting stores while presenting it as average revenue per open store can be arithmetically correct and unfaithful as a service — and a system that identifies the right population but uses stale or incomplete state can be faithful in interpretation and unreliable in production.
The failure is usually not that the narrower statement is false. It is that the authority of a result correct under a narrower definition is allowed to travel beyond the grounds and the definition that made it correct.
No number is entitled to answer this question yet, and the reason is not arithmetic. The population has to be established, the state that population requires has to be shown to be present, and only then is there a question about what may be served.
Establishing the population and establishing a servable answer are two different things, and only the first is in reach here.
Six words this page uses precisely
- Request
- the governed analytical formulation of the user’s purpose.
- Result
- the product of the governed analytical process.
- Answer
- a result served as responsive to the request.
- Servability
- whether the result has the analytical permission required to be served as that answer.
- Standing
- what the result or answer may be treated as, or relied upon for, at a boundary.
- Constitution
- the ratified governed world of analytical meaning, law, support rules, and authority against which serving is adjudicated.
The paper’s own definitions, unaltered. They are here because the words are ordinary and the distinctions are not: result and answer are different things, and so are servability and standing.
Legitimacy — what must remain true
User purpose → analytical intent → governed analytical construction → reliable production → servability → warranted reliance → consequential use
This is an operational cut through the analytical service, not a replacement taxonomy for the foundational domains whose laws the service uses. Different systems may combine functions. Governance requires that the distinctions remain visible enough to adjudicate.
-
Faithfulness
purpose → request → answer
Does the service preserve the user’s purpose as it becomes an analytical request and an answer? Two duties, and only one of them is translation. Fidelity prevents the system from saying something different from what the user means. Enablement helps the user say more precisely what they are trying to know.
Neither authorizes the system to choose silently on the user’s behalf.
-
Reliability
established object → produced result
Can the governed analytical process produce the established result consistently under the relevant conditions? Data availability, state, execution, materialization, reproducibility. Reliability does not create analytical meaning; it preserves and produces what was already formulated and established.
A reliable production path must reproduce and carry forward the object that was actually established.
-
Certainty sufficient for reliance
grounds → warranted reliance
Are the grounds relevant to this result established, preserved and respected as the service crosses from request to answer, and from answer to use? The sufficiency of a ground depends on the exposure the reliance creates.
This is where Analytical Governance defers: the discipline of grounds is developed elsewhere.
Analytical Governance does not develop its own account of what makes grounds sufficient. That upstream discipline — what grounds carry a conclusion, what they establish, where their warrant stops, and whether they can bear the reliance being placed on them — is developed separately in The Ground for Certainty, and Analytical Governance turns those questions into a governed analytical service.
The intent gap
From purpose to governed request.
The first gap is the distance between what a user can initially express and the analytical request that faithfully captures their purpose with the distinctions governance needs. Closing it has two obligations: preserve the purpose, and enable better articulation.
AI and semantic systems can search vocabulary, retrieve definitions, expose governed distinctions, propose interpretations, explain alternatives, and formulate a candidate governed request. This is not merely translation. A good analytical service can expand what a user is able to say, by making the relevant distinctions available to be said.
A user asks for “average revenue.” The service can surface the governed alternatives — among reporting stores, among existing stores, among stores that were open — explain the difference, and let the user choose.
That is enablement. Silently selecting one of them is unauthorized formulation by the serving system.
Enablement must not conceal materially relevant governed alternatives. If the service surfaces a selective set rather than the relevant governed set, that selectivity must itself be governed or disclosed.
The intent gap is closed when the user’s purpose has been formulated — through preservation and, where useful, enablement — as an analytical request explicit enough for independent adjudication.
The servability gap
Faithful request does not imply servable request.
Servable = Support Sufficient AND Analytically Established
Analytical establishment asks whether the requested analytical object exists under the governed analytical model and whether the requested derivation is lawful. Support sufficiency asks whether the evidence and sufficient state this particular request requires are presently available.
A missing feed can leave a lawful request unsupported. An unlawful reduction can leave abundant data unable to establish the requested result. An unresolved population can make a computable denominator analytically unestablished.
Computability does not imply servability.
Servability is not a generic property of a dataset, metric, model or platform. It is a determination about a particular analytical request under current grounds. And a result may be servable and still not be served: servability establishes the analytical permission for the requested answer, while authorization, risk and disclosure conditions determine the serving outcome.
Time has to be typed carefully. A late-arriving or retroactively corrected record does not necessarily change the identity of the analytical object; it may instead change whether the required state was support-sufficient when the answer was served. If the governed definition itself is versioned over time, analytical identity may change too.
Governance responses
Clarify stays inside the constitution. Escalate reaches the constitution’s edge.
The serving vocabulary — what a governed system returns at the machine boundary
-
Serve
The request is determinate, the required analytical and support grounds are established, the result is authorized for the intended use, and no material condition requires separate disclosure.
-
Disclose
The result may be served, but a material condition must travel with it. Disclosure preserves the boundary of the warrant.
-
Clarify
The missing distinction is inside the existing governed world and the requester can resolve it. Clarification protects faithfulness to purpose; it does not create new analytical authority.
-
Refuse
The requested answer cannot be served under current analytical, support, risk, or authorization conditions. Refusal is evidence that analytical permission is real.
The governance-process outcome — across the system boundary
Escalate
Faithful service requires something the current governed world does not possess: new meaning, new evidence, new authority, or qualified review. The request leaves the serving path and enters an authoring, declaration, review or ratification process capable of changing the governed world. It is not a fifth serving mood, and escalation does not produce an unofficial answer.
Clarify choose among governed meanings.
Escalate new meaning, evidence, authority, or qualified review is required before serving can resolve.
The full governance process therefore produces five externally meaningful outcomes. The machine serving vocabulary has four. Those are two different counts of two different things, and collapsing them is how a governance boundary quietly becomes a response enum.
Standing
What may the served result now be treated as?
Servability asks whether a candidate result may be served as the answer. Consequential use creates a further question, and it is not the same one.
Standing is claim- and boundary-specific. A result may stand for exploratory display and not for compensation. A statistical estimate may stand as an estimate and not as a causal claim. A result may require disclosure before publication.
Standing prevents a result from becoming more authoritative merely because it travelled. Conclusions are portable; their grounds are less so.
This is the wound at the top of the page, one boundary later. There, a value correct under a narrower definition was not yet the answer to the question asked. Here, an answer that was entitled to be served is not thereby entitled to everything that might be done with it. In both cases what must not travel unexamined is the authority of the result, and what fixes its limit is the grounds and the definition that earned it.
Risk and authority come after analytical establishment
Cost, security, application risk and authorization can constrain an otherwise established analytical service. They cannot supply a missing analytical ground.
Risk may constrain the right answer. It cannot turn an unestablished answer into the right one.
An unresolved analytical identity, an unsupported population or an unlawful derivation is not a higher-risk version of the requested answer. Once the object and its required support are established, exposure matters: the same result may be acceptable for exploration and unacceptable for compensation, publication or automated action.
Govern the crossings
- purpose becomes a request
- a request becomes a plan
- a plan produces a result
- a result becomes an answer
- an answer becomes action
Analytical service becomes consequential at crossings, and each crossing is an opportunity for authority to travel farther than its grounds.
The component that can produce a candidate result need not be the component entitled to authorize what that result becomes.
AI agents are one application of this crossing discipline. A model may interpret language, formulate a candidate governed request, generate candidate SQL, summarize evidence, or explain an adjudication result. None of those capabilities requires the model itself to carry analytical authority.
A structural execution boundary can close one consequential path independently of predictions about the agent. This is the role of a blast wall: a structural boundary that prevents reasoning output from becoming consequential execution directly. The same principle applies to serving — the agent may propose or explain; the governed serving boundary determines what the result is entitled to become.
Where this sits
Analytics is not governed by one body of law. Analytical Governance coordinates these kinds of interior law without replacing them: it governs the service passage — what must remain true as purpose becomes request, request becomes result, result becomes answer, and answer becomes consequential use. Its subject includes process and practice as well as architecture, because analysts, data systems, semantic systems, AI agents, reviewers and execution controls all have to preserve analytical meaning and authority across handoffs.
- Data governance composes with analytical governance
- Data governance governs the stewardship, access, quality and control of data assets. Analytical Governance governs whether the analytical service is faithfully formulated, sufficiently established, honestly served and appropriately used. The two compose; neither substitutes for the other.
- The Theory of Data supplies interior law to analytical governance
- Laws of governed analytical identity, derivability and consistency. It is narrowly that: not a general ontology of analytical objects, and not the law of every world the service crosses.
- The Statistical Bridge governs a crossing inside analytical governance
- Passages from governed evidence through formal inference to licensed claims. Analytical Governance may compose that crossing into a larger analytical path. It does not replace the Bridge’s law, and it does not adjudicate inference itself.
- The Theory of Certainty supplies the upstream discipline to analytical governance
- What grounds carry a conclusion, what they establish, where their warrant stops, and whether they can bear the reliance being placed on them. Analytical Governance turns those questions into a governed analytical service; it does not restate them.
- Columna is an executable consequence of analytical governance
- Evidence that these distinctions can be embodied in a working system. Not the definition of the category, and the category does not depend on it.
- Frame-QL is one request language for analytical governance
- Convenient as a request boundary because it speaks natively in governed analytical objects. No language or protocol is required by the category — only that every identity-bearing distinction be explicit in the request or uniquely derivable from the governed model.
The research corpus The authority boundary, argued Exhibit B — four requests, four earned verdicts
Conformance
What a conforming service needs, at minimum.
- a way to preserve user purpose while translating human or machine intent into an explicit analytical request;
- a governed analytical representation capable of independently establishing identity, derivation, support requirements and relevant state;
- a reliable production path that preserves what was analytically established;
- a servability gate capable of withholding or qualifying analytical permission;
- a way to preserve standing, conditions, reasons and alternatives as results cross boundaries;
- separation between analytical establishment and later cost, security, application and authorization decisions;
- execution faithful to what governance actually authorized.
And what the framework does not claim
It does not guarantee perfect intent, perfect data, perfect governed declarations or perfect decisions. It does not replace semantic knowledge, statistical inference, security engineering, physical optimization or decision governance. It requires no particular query language, semantic layer or implementation architecture.
It requires that the analytical target, the grounds relevant to serving it, and the authority for consequential use be independently adjudicable somewhere before the service crosses the relevant boundary.
Product consequence
The typing is not only argued. It ships.
Analytical Governance is a category, not a product. But a category that no system has ever embodied is a proposal, and the distinction this page turns on is testable in one place: what a governed engine is actually willing to return.
Escalate does not appear at this boundary. It is a governance action, not a serving mood.
Columna exposes exactly the four serving moods at its machine boundary. Escalate is not among them — not because it was left out, but because it is not a serving verdict. It is what happens when the governed world cannot resolve the request at all.
The block beside this is read from a transcript generated by running the shipped package,
on the deploy path. Nothing in it is transcribed by hand, and the absence of
escalate is verified at build time rather than claimed in copy.
- "outcome": "serve"
- "outcome": "disclose"
- "outcome": "clarify"
- "outcome": "refuse"
The discipline
- Preserve purpose.
- Establish the analytical object and its grounds.
- Produce it reliably.
- Serve only what is servable.
- Preserve standing across crossings.
- Govern consequential use.
The goal is not to formalize every analytical act. It is to ensure that when analytics serves a user, the answer remains faithful to the purpose that called for it and carries no more authority than it has earned.
Read the paper Analytical Governance — Version 2.0
Applied to AI agents Do Not Let Your AI Agent Govern Itself →
See the executable consequence Columna →
The previous doorway Analytical Governance v1.1 →