Workbook

Data Governance Lead

You own: the policies that gate model + prompt promotion, audit integrity, approval workflows, and consent flows. GeneFlow enforces what you write.

What's new for you

WasNow in GeneFlow
Stage transitions on the honor systemApproval gate + hash-chained audit on every transition
Policies in ConfluenceEncoded in tenant settings, enforced in middleware
"Did anyone approve this?" guessworkgenedata_audit_log has requested_by + approved_by
Audit log tamperableSHA-256 chained — tampering breaks the chain

Policy levers

LeverWhereWhat it controls
auto_approve_prodCustomerTenantSettings.geneflowSkip approval for Prod transitions (rare)
model_version.requireApprovalper versionOverride per-model
prompt_version.requireApprovalper prompt versionSame for prompts
transition_reason_requiredtenant settingForce human reason text
approval_two_factortenant setting2-person approver rule

Workflow 1 — Set tenant-level policy

genedata tenants update ACME \
  --geneflow-auto-approve-prod false \
  --geneflow-transition-reason-required true \
  --geneflow-approval-two-factor true

Workflow 2 — Review an approval

When an MLE/PromptEng requests a Production transition, an audit row fires. Reviewers see them in /dashboard/admin/approvals.

-- All open approvals
SELECT id, entity_type, entity_id, requested_by, requested_at, payload
FROM gf_stage_transitions
WHERE tenant_id='ACME' AND approved_at IS NULL AND requested_stage='Production'
ORDER BY requested_at DESC;

Approve via UI or API:

curl -X POST .../api/v2.1/geneflow/transitions/$ID/approve \
  -H "Authorization: Bearer $DGL_TOKEN"

Workflow 3 — Verify audit chain weekly

SELECT * FROM verify_audit_chain('ACME');
-- Expected: { ok: true }
-- If { ok: false, brokenAt: N, id: '…' } → page SRE immediately

Schedule this as a CronJob; alert on failure.

Workflow 4 — Quarterly access review

-- Who has geneflow:transition in this tenant?
SELECT user_id, scopes FROM user_tokens
WHERE tenant_id='ACME' AND 'geneflow:transition' = ANY(scopes);

-- Their actual usage last 90 days
SELECT actor->>'userId', COUNT(*) AS transitions
FROM genedata_audit_log
WHERE tenant_id='ACME' AND action='geneflow.stage.transition'
  AND ts >= now() - INTERVAL '90 days'
GROUP BY actor->>'userId' ORDER BY 2 DESC;

Revoke tokens for users not actively transitioning.

Workflow 5 — Sensitive prompt review

Some prompts handle PII / financial / health data. Flag them:

prompts.set_tag("customer_support", version=2,
                key="data_sensitivity", value="contains_pii")

Then your weekly review query:

SELECT name, version, current_stage
FROM gf_prompt_versions
WHERE tenant_id='ACME' AND tags->>'data_sensitivity' IS NOT NULL
ORDER BY name, version;

Confirm every PII-touching prompt has an approver chain.

Common gotchas

  • Don't disable approval globally unless it's a dev tenant. The audit chain still works, but the gate is gone.
  • Audit chain verification is per-tenant — run for every prod tenant on a schedule.
  • Approver != requester — two-factor approval enforces this in DB; don't override in code.

Where to go next