# Governed Data and Assurance Product Package This package composes Datasources, Dataflow, Reporting, Search, Risk Compliance, Policy, Audit, and Access. Connectors may acquire external data, but Datasources owns the governed catalogue and immutable snapshots; Dataflow owns transformation definitions and runs; Reporting owns measures and presentation; Risk Compliance owns controls, findings, and effectiveness review. ## Reference journey 1. Register a typed datasource with source authority, purpose, classification, owner, freshness, and correction policy. 2. Acquire or upload an immutable source state. 3. execute a versioned flow and retain intermediate materializations and provenance; 4. publish a report or decision input against exact source and flow revisions; 5. link obligation, governed object, risk, control, evidence, finding, corrective measure, and effectiveness review; and 6. search current authorized objects while preserving ownership and access rechecks. ## Reference-readiness gates The artifact remains a `product` package. Promotion to `reference` requires: - a target-tested monthly-data and sanctions-screening fixture with expected outputs and complete provenance; - database/object-storage backup and restore plus interrupted-run recovery; - security evidence for datasource credentials, staged data, intermediate states, search documents, and assurance references; - operator runbooks for stale sources, failed runs, index rebuilds, and graph reconciliation; - accessibility evidence for the catalogue, graph editors, result inspection, reports, and assurance graph; - privacy evidence for minimization, purpose, retention, field visibility, and aggregate disclosure; and - version-pinned user and administrator documentation. Optional Connectors, Files, Notifications, and Workflow Engine integrations must remain capability-based and absence-safe.