Architecture Governance

Every organisation of any size already has architecture governance. The only question is whether it is deliberate or accidental. When it is accidental, it lives in the reflexes of a few senior engineers, in the escalations that reach the CIO, and in the quiet accretion of incompatible choices that nobody decided but everybody now maintains. Deliberate governance is not more control than that. Often it is less. What it adds is intent: a shared understanding of which decisions are consequential enough to warrant collective attention, who is entitled to make them, on what basis, and how the organisation learns from the ones it gets wrong.

This piece takes a specific stance. The purpose of architecture governance is not to prevent bad decisions by inspecting every choice. That model does not scale, and where it is attempted it produces a queue, a bottleneck, and a thriving black market in workarounds. The purpose is to make the good decision the easy one and the coherent path the default one, so that most decisions never need a board at all, and the board reserves its scarce attention for the few that genuinely shape the estate. Governance that achieves this enables delivery. Governance that forgets it becomes the thing delivery routes around.

What Nashua offers hereEngagements that make coherent architecture the default without turning governance into a bottleneck.See the engagements

Why governance is contested now

Architecture governance has a reputation problem, and it is largely deserved. For two decades the dominant image was a review board that met fortnightly, demanded a template nobody had time to read, and returned verdicts weeks after the decision had already been made under delivery pressure. That model was built for an era of long release cycles and central control, where an architect could plausibly review the material choices of the estate because there were not many of them and they moved slowly.

That era has ended, and the reasons it ended are precisely why governance now matters more, not less. Delivery has federated into product teams that ship continuously and own their own stacks. Cloud has turned provisioning into an API call, which means an engineer can commit the organisation to a new database, a new region, or a new licensing posture in an afternoon, with no procurement gate to slow them down. The surface area of consequential decisions has multiplied while the traditional mechanism for reviewing them has stayed the same size. The result is drift: not dramatic failure, but a slow divergence where every team is locally reasonable and the estate as a whole becomes incoherent, expensive to change, and impossible to reason about.

The stakes have risen in parallel. Regulatory regimes such as DORA and NIS2 now ask organisations to demonstrate that architectural and operational decisions were made with due diligence, which is a governance question before it is a technical one. The point is not to reinstate the fortnightly board. It is to recognise that coherence no longer emerges by itself, and that the discipline which produces it has to be redesigned for a federated, fast-moving estate rather than abandoned as an artefact of a slower age.

The four instruments and how they relate

Architecture governance is not a single mechanism. It is a system of four instruments that only work together, and most dysfunction comes from operating one or two of them in isolation. The first is principles: the durable statements of reasoning that express what the organisation values and why. A good principle is not a platitude. It carries an implication and a rationale, so that when two principles conflict, as they will, the trade-off can be argued on stated grounds rather than on seniority. Principles outlive any individual decision and give the other instruments their justification.

The second instrument is standards: the concrete, testable expression of principle. Where a principle says the organisation prefers managed services to self-operated infrastructure, a standard names the sanctioned managed services, the conditions of their use, and ideally encodes the check that verifies compliance. Standards are where intent becomes actionable. Without them, principles are decoration; without principles above them, standards are arbitrary rules that teams rightly resent.

The third instrument is decision rights: an explicit map of who is entitled to decide what, at which altitude. This is the instrument organisations most often leave implicit, and the omission is expensive, because in its absence every decision is potentially everyone's business and therefore nobody's clear responsibility. The fourth instrument is review, the board or forum where the small set of genuinely consequential and genuinely contested decisions are deliberated. Around all four sits the exception mechanism: the disciplined, time-boxed granting of dispensations for choices that breach a standard for a documented and defensible reason. An organisation that cannot grant exceptions cleanly will find its teams taking them silently, which is drift by another name.

Reviewbounded deliberation for the consequential fewDecision rightswho decides what, at which altitudeStandardsthe testable, often encoded, expression of intentPrinciplesthe shared reasoning that outlives any decision
Governance works as a stack in which each layer draws its authority from the one beneath it.

From gates to guardrails

The most important shift in contemporary practice is the move from gates to guardrails, and it deserves precision because the phrase is often used loosely. A gate is a synchronous checkpoint: work stops, a human inspects, and a verdict is issued before delivery may proceed. A guardrail is an encoded constraint that operates continuously and largely without human intervention, permitting anything within bounds and flagging or blocking only what falls outside them. The organisations getting governance right are converting as many gates as they can into guardrails, and reserving human review for the residue that genuinely requires judgement.

This is where policy as code has become central. Landing zones, sanctioned infrastructure modules, and pipeline checks encode standards directly into the paths engineers already use, so that the compliant choice is also the fastest one. The architectural decision record, or ADR, has matured from a nicety into the connective tissue of federated governance: a lightweight, versioned note capturing what was decided, the options considered, and the reasoning, kept next to the code rather than in a separate repository nobody visits. ADRs let governance become asynchronous and legible without a meeting.

Two further trends shape the field. Federated or team-topology-aligned governance distributes decision rights deliberately, pairing autonomous product teams with a thin enabling function and a shared platform that carries the paved road. And the rising volume of change, now amplified by AI-assisted development that lets teams produce and provision far more, faster, is straining any model that depends on human inspection of each decision. The direction of travel is unambiguous: governance that scales is governance that is mostly encoded, mostly asynchronous, and mostly invisible until a genuine boundary is approached.

Design principles for governance that enables

Governance is itself a designed system, and the same rigour applied to a technical architecture should apply to it. The first design principle is subsidiarity: decisions should be made at the lowest level competent to make them well. A choice that affects only one team should be that team's to make; only a choice whose consequences cross boundaries, that commits the organisation to a shared future, or that is expensive to reverse, warrants elevation. Getting this altitude right is most of the craft. Set it too low and the board drowns; too high and teams are infantilised and route around the process.

The second principle is proportionality. The weight of the process should match the weight and reversibility of the decision. Jeff Bezos's distinction between one-way and two-way doors is the useful lens: reversible decisions should be delegated and made quickly, and only the irreversible or near-irreversible ones deserve the ceremony of a board. The third principle is that the paved road must be genuinely the easiest path. If the compliant option is slower, more painful, or less documented than the improvised one, no amount of policy will hold, because engineers optimise for shipping and they are right to. Governance earns compliance by investment in the sanctioned path, not by enforcement against the alternatives.

The fourth principle is transparency of reasoning. A decision recorded with its rationale can be revisited when circumstances change; a decision issued as a bare verdict cannot, and it calcifies. The fifth is that review must be time-boxed and default-permissive: a decision not blocked within a defined window proceeds. This single inversion, from opt-in approval to bounded objection, is what keeps governance from becoming the queue that delivery fears. Together these principles describe governance that constrains the few things that matter and gets out of the way of everything else.

The characteristic failure modes

The ivory tower board. A group of senior architects, removed from delivery, reviews decisions against an idealised model of the estate rather than its reality. Their verdicts are technically defensible and practically ignored, and the gap between the sanctioned architecture and the running one widens with every sprint. The cure is not more authority for the board but membership that includes the people who build and operate, and a mandate scoped to genuinely cross-cutting concerns.

The rubber stamp. The opposite pathology. The board meets, but under delivery pressure it approves everything, because saying no has a visible cost and saying yes has a deferred one. Governance becomes theatre, consuming time while changing nothing. This usually signals that the board is reviewing decisions at the wrong altitude, spending its attention on choices that should have been delegated and therefore having none left for the ones that matter.

Exception amnesia. Dispensations are granted verbally or in a ticket and then forgotten. Each was reasonable in isolation, but nobody tracks the accumulation, and after two years the estate is a museum of temporary exceptions that became permanent. A dispensation without an expiry date and an owner is not an exception, it is a silent standard change. Standards without stewards is the adjacent failure: a rule is published, the author moves on, the context that justified it is lost, and teams comply with something nobody can now explain or is empowered to revise. And the bottleneck, the failure the whole discipline exists to avoid: review becomes a synchronous queue that delivery must wait in, and the organisation's most capable engineers spend their days routing around governance rather than through it, taking their real decisions where the board cannot see them. Every one of these modes converts governance from an enabler into an obstacle, and every one is a design fault in the governance system, not a failure of the people subject to it.

How Nashua works on this

Nashua approaches architecture governance as a system to be designed and tuned, not a policy to be issued. We begin by mapping the governance an organisation already has, because there is always some, and it is usually undocumented. Which decisions currently escalate, and to whom? Where do teams quietly work around the stated process, and what does that reveal about where the process is miscalibrated? Where is drift already accumulating? This diagnostic is deliberately unflattering, because the honest picture of how decisions are really made is the only sound foundation for changing it.

From there we work on the four instruments in concert. We help articulate principles that carry rationale rather than slogans, and we translate them into standards that are specific enough to be testable. We make decision rights explicit, drawing the altitude line so that the great majority of decisions sit clearly with the teams and only the consequential minority reach a board. We design that board for speed and legitimacy: the right membership, a tight remit, time-boxed and default-permissive review, and decisions recorded as ADRs so the reasoning survives. Crucially, we treat the exception mechanism as first-class, with dispensations that carry owners, expiry dates, and a register that turns the accumulation of exceptions into a visible signal rather than a hidden liability.

Wherever a standard can be encoded, we prefer the guardrail to the gate, embedding checks into landing zones, pipelines, and the paved road so that compliance is the path of least resistance rather than an act of virtue. We are candid about proportion: a smaller organisation needs a lighter apparatus than a regulated enterprise, and imposing heavy governance on a context that cannot sustain it produces the theatre we are trying to eliminate. Our aim throughout is a governance function that a client can operate without us, because governance that depends on its consultants is not governance, it is dependency.

Where Nashua makes the difference

What distinguishes Nashua is the refusal to treat governance as a document exercise. Anyone can supply a principles catalogue and a board charter; the difference lies in whether the resulting system actually changes how decisions are made and whether it keeps drift in check without becoming the bottleneck everyone predicted. We measure our work by that outcome: are consequential decisions being made faster and more coherently, are teams choosing the paved road because it is the easiest one, and is the exception register shrinking rather than quietly growing? Governance that improves those signals is working. Governance that only produces artefacts is not, whatever its documentation says.

There is also a practical corollary that changes what the work is permitted to assume. When an engagement calls for a capability that does not yet exist, it need not wait on a procurement cycle or a vendor's roadmap. The Nashua 360 Enterprise Platform is built to accommodate almost any feature at pace, through extreme vibe coding: what is needed is described in plain language and generated quickly, but always within firm architecture principles and under stringent quality assurance, so that speed never comes at the cost of coherence, security or control. The effect is strategic rather than merely convenient. It moves the make-or-buy line, keeps optionality cheap, and lets the architecture follow the strategy rather than the strategy bending to whatever happened to be on a shelf.

Our second differentiator is that we stay long enough to tune. A governance system set up on paper and left alone will drift out of calibration as the organisation changes, the altitude line that was right last year becoming wrong this year as teams mature and the estate evolves. We treat governance as something to be observed in operation and adjusted, watching where escalations cluster, where exceptions accumulate, and where teams route around the process, and we read those as design feedback rather than as compliance failures. Finally, we bring the practitioner's discipline of proportion. We will argue a client out of governance they do not need as readily as we will build the governance they do, because the credibility of the whole discipline rests on it enabling coherent delivery rather than obstructing it. That is the test we hold ourselves to, and it is where the difference is made.