Skip to content

docs: Update to project governance - #1207

Open
sshiells-scottlogic wants to merge 13 commits into
finos:mainfrom
sshiells-scottlogic:claude/governance-proposal-updates-5eb234
Open

docs: Update to project governance#1207
sshiells-scottlogic wants to merge 13 commits into
finos:mainfrom
sshiells-scottlogic:claude/governance-proposal-updates-5eb234

Conversation

@sshiells-scottlogic

Copy link
Copy Markdown
Contributor

Summary

Steering Committee governance updates

Implements the CCC Steering Committee Governance Proposal and follow-up review feedback: gives the committee a defined role in decision-making and releases, and retires the Change Management Board.

  • Roles: grouped all committee roles under one heading — Members, Chair/Vice Chair, and Cyber Security Leads. Added Chair/Vice Chair officers (eligibility, selection, 2-year terms, vacancy) and a member minimum-participation guideline (attend ≥ half of meetings over a rolling 6 months, else a discussion with the Chair).
  • Voting: Steering Committee votes are now held as PRs against the Decision Log (DECISIONS.md) — approve/reject on the PR; passed PRs merge as accepted, rejected ones merge with the outcome recorded. Chair closes the vote once clear or after 2 weeks. Passes by majority of participating members with a floor of ≥ 2 FSI-seat approvals (Steering Committee decisions only). Added DECISIONS.md.
  • Release governance: removed the Change Management Board entirely; releases now need two different non-author approvers, the WG lead plus a Cyber Security Lead. Updated the release guideline, issue template, and flow diagram.
  • Roadmap: now issue-driven — community raises issues, the committee prioritises them in regular meetings, and the "north star" direction is shared with the community/website.
  • Meetings: routine meetings are private/invite-only on a committee-set cadence; each opens with an antitrust reminder.

Related issues

Closes #1158 1158

Checklist

sshiells-scottlogic and others added 13 commits August 3, 2026 10:14
Implements the CCC Steering Committee Governance Proposal across the
governance docs:

- charter.md: add Officers (Chair/Vice Chair), Release Governance (FSI
  Cloud Leads + release sign-off), Decision Log, Roadmap Planning and a
  Meeting conduct (antitrust) item; revise Voting to a majority of
  participating members with a >=2 FSI-seat floor, plus advance/absentee
  voting; revise Quorum accordingly; record open questions.
- DECISIONS.md: new Steering Committee decision-log index.
- releases/README.md: layer FSI Cloud Lead release sign-off and roadmap
  planning onto the existing process.
- README.md: add a Designated FSI Cloud Leads table.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Rename the release sign-off / roadmap delegate from a new "FSI Cloud
Lead" role to the existing Cyber Security Lead role already recorded in
the README Steering Committee table (the per-firm Alternate). Removes
the redundant designated-leads table in favour of that existing column.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
A Working Group lead may also be a designated Cyber Security Lead, so
independence is not automatic. Require the WG-lead and Cyber Security
Lead sign-offs to be two different people, and where the relevant WG
lead holds both roles, require the second sign-off from a different
Cyber Security Lead.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Drop the Open questions section and the references to it (the Officer
term cross-link and the now-unused recusal-expectations link).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Reword the Routine business rationale more formally.
- Roadmap sessions are timed after OSFF NY/London (not around and
  after), and direction may draw on feedback and observations gathered
  at those events.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Applies review feedback on the governance proposal:

- Group role definitions (Members, Chair/Vice Chair, Cyber Security
  Leads) under a shared "Roles" heading in the charter; keep the
  functional release-oversight process under "Release Governance".
- Add a Routine meetings subsection: private, invite-only working
  meetings on a committee-set cadence, funnelling wider engagement to
  the public quarterly call and all-hands.
- Add minimum-participation / auto-vacancy mechanisms for committee
  members and Cyber Security Leads, with thresholds left for the
  committee to set.
- Delete the Change Management Board entirely (cmb.md and the cmb/
  folder); streamline the release flow to two non-author approvers
  (WG lead + Cyber Security Lead) and preserve the Release Manager
  role. Update the release proposal issue template accordingly.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace agenda-flagged in-meeting/advance voting with an asynchronous
pull-request model:

- Votes are raised as a PR against DECISIONS.md; members approve or
  reject on the PR.
- If passed, the PR is merged as accepted; if not passed, the outcome
  is set to rejected and the PR is merged anyway, so every decision is
  recorded either way.
- Redefine "participating members" as those who record an approve/reject
  on the PR; remove the advance/absentee voting section; rework
  abstention and quorum accordingly.
- Update DECISIONS.md to document the PR-based process.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- The Chair closes a Decision Log vote once the outcome is clear, or at
  the latest two weeks after the PR was opened.
- Clarify that the two-FSI-approval floor applies only to Steering
  Committee decisions on the Decision Log, not to ordinary content,
  catalog, or release pull requests.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the twice-a-year open roadmap session with an ongoing,
issue-driven model: the community raises suggestions and features as
GitHub issues, the Steering Committee reviews and prioritises them in
its regular meetings, and the high-level "north star" direction is
communicated to the community and can be shown on the website.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
- Committee members: attend at least half of meetings over a rolling
  six-month window; falling short prompts a discussion with the Chair
  about whether they remain best placed to hold the seat (rather than
  automatic vacancy).
- Cyber Security Leads: sign off at least one release over a rolling
  six-month window, else the firm re-confirms or re-designates.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
The release flow diagram has been updated, so the note flagging it as
out of date is no longer needed.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Replace the release-process diagram with the revised version reflecting
the streamlined flow (Working Group lead plus Cyber Security Lead
sign-off, no Change Management Board).

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
@sshiells-scottlogic
sshiells-scottlogic requested review from a team as code owners August 24, 2026 07:50
@netlify

netlify Bot commented Aug 24, 2026

Copy link
Copy Markdown

Deploy Preview for common-cloud-controls ready!

Name Link
🔨 Latest commit 5eafca3
🔍 Latest deploy log https://app.netlify.com/projects/common-cloud-controls/deploys/6a8bf7b6c8d811000890af63
😎 Deploy Preview https://deploy-preview-1207--common-cloud-controls.netlify.app
📱 Preview on mobile
Toggle QR Code...

QR Code

Use your smartphone camera to open QR code link.

To edit notification comments on pull requests, go to your Netlify project configuration.

@linux-foundation-easycla

linux-foundation-easycla Bot commented Aug 24, 2026

Copy link
Copy Markdown

CLA Signed
The committers listed above are authorized under a signed CLA.

One or more co-authors of this pull request were not found. You must specify co-authors in commit message trailer via:

Co-authored-by: name <email>

Supported Co-authored-by: formats include:

  1. Anything <id+login@users.noreply.github.com> - it will locate your GitHub user by id part.
  2. Anything <login@users.noreply.github.com> - it will locate your GitHub user by login part.
  3. Anything <public-email> - it will locate your GitHub user by public-email part. Note that this email must be made public on Github.
  4. Anything <other-email> - it will locate your GitHub user by other-email part but only if that email was used before for any other CLA as a main commit author.
  5. login <any-valid-email> - it will locate your GitHub user by login part, note that login part must be at least 3 characters long.

Alternatively, if the co-author should not be included, remove the Co-authored-by: line from the commit message.

Please update your commit message(s) by doing git commit --amend and then git push [--force] and then request re-running CLA check via commenting on this pull request:

/easycla

@jarias-lfx

Copy link
Copy Markdown

/easycla

@robmoffat

Copy link
Copy Markdown
Member

@sshiells-scottlogic you're good now on the EasyCLA

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Revamp governance docs and README to reflect current project structure and roles

3 participants