<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Concepts on Open Workload Governance</title><link>https://openworkloadgovernance.io/docs/concepts/</link><description>Recent content in Concepts on Open Workload Governance</description><generator>Hugo</generator><language>en-us</language><atom:link href="https://openworkloadgovernance.io/docs/concepts/index.xml" rel="self" type="application/rss+xml"/><item><title>Workloads</title><link>https://openworkloadgovernance.io/docs/concepts/workloads/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://openworkloadgovernance.io/docs/concepts/workloads/</guid><description>&lt;p&gt;A Workload describes a governed service or other workload through its metadata, ownership,
classification, identities, resources, capabilities, dependencies, and access intents. The example
describes &lt;code&gt;shop-api&lt;/code&gt;, a customer-facing webshop API with &lt;code&gt;metadata.type: service&lt;/code&gt;. The permitted
workload types have not yet been defined.&lt;/p&gt;
&lt;h2 id="questions-a-workload-answers"&gt;Questions A Workload Answers&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;What is this workload, and what type of workload is it?&lt;/li&gt;
&lt;li&gt;Who owns it, and who can approve governance actions?&lt;/li&gt;
&lt;li&gt;Which environment and data classification apply?&lt;/li&gt;
&lt;li&gt;Which identities and resources are associated with it?&lt;/li&gt;
&lt;li&gt;Which APIs and scopes does it provide?&lt;/li&gt;
&lt;li&gt;Which services and resources does it require?&lt;/li&gt;
&lt;li&gt;Which actions are intended between identities and targets?&lt;/li&gt;
&lt;li&gt;Which change-management, approval, and control requirements apply?&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="description-is-not-enforcement"&gt;Description Is Not Enforcement&lt;/h2&gt;
&lt;p&gt;Declaring ownership, required scopes, or an access intent does not provision an identity, grant
access, or authorize a deployment. Participating systems need explicit validation and enforcement
contracts. The draft describes desired governance relationships, not an implemented control plane.&lt;/p&gt;</description></item><item><title>References</title><link>https://openworkloadgovernance.io/docs/concepts/references/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://openworkloadgovernance.io/docs/concepts/references/</guid><description>&lt;p&gt;OWG does not prescribe an identity provider. The Workload example connects external systems using
named references and direct &lt;code&gt;ref&lt;/code&gt; values, rather than defining users, groups, or teams itself.&lt;/p&gt;
&lt;h2 id="named-references"&gt;Named References&lt;/h2&gt;
&lt;p&gt;Ownership lists names whose external targets are declared in &lt;code&gt;references&lt;/code&gt;:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="background-color:#f0f0f0;-moz-tab-size:4;-o-tab-size:4;tab-size:4;"&gt;&lt;code class="language-yaml" data-lang="yaml"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#062873;font-weight:bold"&gt;ownership&lt;/span&gt;:&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#bbb"&gt; &lt;/span&gt;&lt;span style="color:#062873;font-weight:bold"&gt;owners&lt;/span&gt;:&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#bbb"&gt; &lt;/span&gt;- omada:team&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#bbb"&gt; &lt;/span&gt;- servicenow:group&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#bbb"&gt;&lt;/span&gt;&lt;span style="color:#062873;font-weight:bold"&gt;references&lt;/span&gt;:&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#bbb"&gt; &lt;/span&gt;- &lt;span style="color:#062873;font-weight:bold"&gt;ref&lt;/span&gt;:&lt;span style="color:#bbb"&gt; &lt;/span&gt;omada://team/shop-team&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#bbb"&gt; &lt;/span&gt;&lt;span style="color:#062873;font-weight:bold"&gt;name&lt;/span&gt;:&lt;span style="color:#bbb"&gt; &lt;/span&gt;omada:team&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#bbb"&gt; &lt;/span&gt;- &lt;span style="color:#062873;font-weight:bold"&gt;ref&lt;/span&gt;:&lt;span style="color:#bbb"&gt; &lt;/span&gt;servicenow://group/customer-platform&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#bbb"&gt; &lt;/span&gt;&lt;span style="color:#062873;font-weight:bold"&gt;name&lt;/span&gt;:&lt;span style="color:#bbb"&gt; &lt;/span&gt;servicenow:group&lt;span style="color:#bbb"&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;code&gt;omada:team&lt;/code&gt; is a local reference name in this example, not a universal subject type. Matching it to
the reference entry identifies &lt;code&gt;omada://team/shop-team&lt;/code&gt; as the external target. The example also
names roles, a business service, a component, and a repository.&lt;/p&gt;</description></item></channel></rss>