Nothing is wrong, nothing is canonical
Every cut of the business is defensible on its own. None of them has been ruled the company position, because nobody was given the authority to rule.
Operating model for governing what counts inside the company — metric definitions, change control, restatement policy, the evaluation stack, and the board-grade number that survives a finance review.
Most companies do not have a measurement problem. They have an authority problem wearing measurement clothes. Reporting volume compounds on its own, because producing another cut of the business requires no permission from anyone. Evidence strength does not move at all unless something rules on which definition counts, who may change it, and what happens when a published number turns out to be wrong. Those are two different axes, and only one of them scales for free.
Reporting is everywhere. Evidence is not.
This playbook governs the semantics — definitional authority and decision rights over what a number means. It is deliberately not a media-measurement or attribution engagement, and it does not sit in the plumbing: that belongs to Enterprise Data Collaboration.
Measurement governance is the work of deciding what counts, inside a company, and of assigning the authority to change that answer. It is not analysis and it is not tooling. It sets which definitions are canonical, who owns each one, how a definition may change, what triggers a restatement of a published number, how much proof each decision actually requires, and which narrow set of numbers is fit for a board.
A number with no owner is not a shared number. It is several numbers wearing one name.
The tell is rarely a bad analyst or a weak tool. It is an organisation where every number is defensible and none is canonical — and it shows up as the same operating symptoms every time.
Most attempts to fix this reach for a better instrument. But the instrument is downstream of the definition, and the definition is what nobody owns.
The question this playbook answers is not "how should we measure that?" It is "who decides what it means, and what happens when they change their mind?"
A metric is governed in five layers. Most organisations hold change control over the bottom two — instrumentation and definition — and assume the three above them. That assumption is the exposure, because a review does not enter at the bottom. It enters at attestation, three layers above anything under control, and works downward from there.
what is observed
The events, sources and collection rules the number is built from. This layer is normally versioned, which is why teams believe the metric above it is versioned too.
Today Usually change-controlled · Sits with Data platform & engineering
what it means
The wording that says what counts: the population, the window, the filter, the cut-off. Written down in most companies, owned in very few.
Today Usually written down · Sits with The named definition owner
how it is derived
The derivation from source to number. This is where a change is most often shipped by overwriting the history rather than restating it on the record.
Today Restated silently · Sits with Analytics & data platform
which surface shows it
The deck, the dashboard and the board pack. Each carries the same label over a different number, and none of them says which one is the company position.
Today Surfaces disagree · Sits with Finance, RevOps & comms
who signs that it is right
The layer that says a named person stands behind the number. It is the layer with no owner — and the layer the buyer’s finance review enters at.
Today Nobody signs · Sits with Unassigned in most companies
Governing the bottom two layers and assuming the top three is not governance. It is a versioned foundation under an unversioned answer.
Almost none of these are arithmetic failures. They are failures of authority — nobody ruled, nobody owned it, nobody wrote down what would happen next.
Every cut of the business is defensible on its own. None of them has been ruled the company position, because nobody was given the authority to rule.
The derivation changes, the history is overwritten rather than restated, and last period stops being comparable to this one.
A metric no function owns is not a shared metric. It is several metrics wearing one name, and none of them can be changed or defended.
With no restatement policy, the decision to disclose an error is made in the room where the number is already wrong, by the person with the most to lose.
Where a number depends on defensible choices, whoever makes the choices owns the answer — and it is rarely the party the answer is presented to.
The moment a definition is handed to something that optimises against it, it stops describing the thing it named and starts describing the effort to move it.
A claim checked by the party who profits from the claim is not a check, however good the checking is.
A proof standard set by habit rather than by the decision buys cost without buying a new answer — and starves the decisions that needed the spend.
The clearest published case is an advertising one, but the mechanism is general: researchers re-measured a set of real campaigns under 54 defensible methodology combinations without changing anything about the campaigns, and 83% of them flipped from positive to negative depending on which defensible recipe was used — one campaign, fifty-four defensible answers. Nothing there is a maths error. Every recipe was legitimate. What was missing was a rule about which one counts, and a party with standing to make it.
Where a number depends on defensible choices, whoever makes the choices owns the answer. Governance decides whether that party is you.
A canonical metric is a record, not a label: a written definition, one accountable owner, lineage traceable from source to number, and a dated version. Every consumer reads that record. The wording and the audience change at the surface; the definition does not.
| Field | What it fixes | What happens without it |
|---|---|---|
| Definition | What counts, written down: population, window, filter, cut-off. | The name is shared and the meaning is not, so each consumer resolves it locally. |
| Owner | One accountable name with the authority to rule on a change — and to refuse one. | Nobody can approve a change, so nobody can stop one either. |
| Lineage | Source to number, traceable by someone who did not produce it. | The number cannot be rebuilt, which makes a restatement a claim rather than a correction. |
| Version | Changes dated, the prior definition retired rather than deleted. | Comparison across the change becomes impossible, quietly and without warning. |
This is also where multi-system reconciliation stops being a modelling exercise. When three systems each report the same event and disagree, the gap is often not a broken pipeline — it is three different windows, filters and cut-offs, each defensible, none of them ruled on. Align the definitions and a real chunk of the disagreement resolves itself. What is left after that is the part worth adjudicating — and now you can, because you are comparing like with like.
Without the record, the metric name is the only thing shared. Four consumers then answer for themselves, and one name comes back as four numbers.
Each metric family gets exactly one named definition owner. Other functions are consulted, one holds a veto over a change that would make its own system silently wrong, and some have no standing at all — stated explicitly, so the absence is a decision rather than an oversight.
| Metric family | Owns the definition | Can veto a change | Consulted | Why the veto sits there |
|---|---|---|---|---|
| Revenue recognised | Finance | Data platform | Product | A restatement nobody can rebuild in the record is a claim, not a correction. |
| Active customer | Product | Finance | Sales, data platform | The number leaves the building in the board pack, so it cannot move without a restatement. |
| Qualified pipeline | Sales | Finance | Product, data platform | The forecast is built on it, so a redefinition mid-quarter reprices the commitment. |
| Identity join key | Data platform | Product | Finance, sales | Every event joins on it, so a silent change moves every metric downstream at once. |
Structural Vendor-neutral metric families and functional labels. The families are shaped to each company; the rule that every one of them has a single owner is not.
One named person per metric. Rules on every proposed change, and may refuse.
One function that would be materially wrong if the change shipped. A veto with no window is an argument.
Named in the impact assessment, heard before the ruling, not able to block it.
Stated explicitly, so the absence is a decision on the record rather than an oversight.
A metric nobody owns is not a shared metric. It is four metrics with one name, and none of them can be changed, refused, or restated.
A governed change clears five gates before it reaches anything that reads the number. Ungoverned, the same change enters as a filter edit on a dashboard, passes through five gates that are not there, and every downstream number moves with nothing on the record to say it did.
what changes, and why now
A named person asks for the change in writing before anything moves. Changing a definition is a request that gets answered, not an edit that gets made.
who reads this number downstream
List every consumer of the definition before the change is considered. If you cannot name who reads the number, you cannot know what the change breaks.
one name signs it, or refuses
One owner per definition, holding the right to refuse. A change nobody can veto is not governed.
the old one is retired, not lost
The prior definition is retired rather than overwritten. Keeping it is what makes a comparison across the change possible at all.
dated, with the restatement
Readable by anyone holding an old number, and carrying the restatement of the periods the new definition now covers differently.
A version bump retires the old definition. It does not delete it — keeping the retired version is the only thing that makes a comparison across the change possible at all.
Two policy lines — how large a miss counts, and how long before the record hardens — sort every correction into one of four responses. Both lines are drawn in advance, by the policy. Drawn afterwards, the disclosure decision falls to whoever is most embarrassed by it.
| Response | When it routes here | What happens to the number | Who is told |
|---|---|---|---|
| Correct silently | Below the materiality threshold, caught before the number moved anyone | Corrected in place and logged | The change log |
| Annotate | Below the threshold, but the figure has already travelled | The figure stands | A footnote travels with it |
| Restate and notify | Above the threshold, still inside the clock | The number is reissued | Everyone who acted on it |
| Restate and re-file | Above the threshold, and already consumed as the board-grade number | Reissued and the record re-filed | The board, in the next pack |
What size of miss counts as material — decided while nobody is embarrassed.
How long before the record hardens and a correction becomes a restatement.
A named owner, not the room. A restatement with no signature is a new number pretending to be the old one.
The notice list, and the order it runs in — written before it is needed.
Silent does not mean hidden. The quietest of the four responses still writes to the change log — the log is the record either way.
Four layers, cheapest to most expensive. Each one removes a kind of doubt the layer below it cannot touch, and each costs more than the last. None of them makes a number true; each makes it harder to dismiss. So the instruction is not "climb to the top" — it is that the decision sets the ceiling. Stop at the cheapest layer that clears the decision the number has to carry, because every layer past that is cost without a new answer.
| Layer | What it earns | What it defends against | What it costs | Justified by |
|---|---|---|---|---|
| Internal reconciliation | You can rebuild it | A total that exists in only one system | Your own people, your own data | A call you can reverse next week |
| Holdout or incrementality test | It survived a counterfactual | Correlation wearing a causal label | Spend you withhold on purpose | Moving budget between lines, and defending it |
| Third-party verification | Someone with nothing riding on it checked | A claim checked by the party who profits from it | A vendor, a schedule, your data in their hands | A claim you publish, or put in a contract |
| Accreditation | The number is transactable | Proof that was true once and never re-checked | An annual clock you never get off | A number other parties transact against |
Accreditation is not a stronger verification. It is a different object: verification proves a method held, accreditation proves a number is transactable. Read as a parts list, it needs four components — and the last one is the one everybody skips.
Accepted by both sides before the trade, not asserted afterwards by the party being measured.
Somebody with nothing riding on the answer. Otherwise the check is the claim, restated.
Renewed rather than won once. Evidence has a clock, and the clock is the product.
The component everyone skips. Drop it and the other three are decoration.
The gap between a claim taken on faith and the same claim carrying proof the counterparty accepts has a price — the evidence premium. It is not collected by whoever has the best number. It goes to whoever can produce a number the other side accepts without reopening the negotiation.
Every governed metric should carry an answer to one question: what would show this is wrong? A number with no falsifier has no evaluation layer at all, however many dashboards render it.
Observation is not lost gradually. It is withdrawn in events: a platform restricts what can be seen, an event was never instrumented in the first place, or the record exists and somebody else holds it. Each break removes a different observation — and the number keeps reporting anyway, which means something has to stand where the observation used to be.
The chain is cut mid-record
What is lost The same subject, seen in two different places.
A modelled estimate A number produced, not a number observed.
Governance decides Who owns the model, and what forces a restatement.
Nothing here to withdraw
What is lost The event itself, which no instrument ever saw.
An agreed convention A definition both sides accept before the count.
Governance decides Who holds the pen, and what change control applies.
Observed, but not by you
What is lost Access to a record that does exist somewhere.
A commercial term What the contract returns, at what grain, by when.
Governance decides What you may audit, and what you may withdraw.
None of the three substitutes is a measurement. Each is a claim somebody negotiated, which makes the choice between them a decision right rather than a methodology detail. The same point runs through the constitutional question underneath restricted observation: the test of a system that limits what can be seen is not the information flows, it is who decides.
The metric keeps its name through every substitution. Only the record underneath changes — which is precisely why the record has to say so.
Board-grade is a property of governance, not of precision. Every number the company produces enters the funnel, and four gates remove numbers rather than decimals. What clears all four is a small set — narrow by construction, because narrowness is what it means for a number to carry a decision.
| Gate | The question it asks | What falls out here |
|---|---|---|
| An agreed definition | Measured against whose definition? | Undefined — the definitions disagree and nobody has ruled. |
| A reproducible result | Same inputs, same number, run by anyone? | Unreproducible — it cannot be rebuilt from source. |
| Independent observation | Examined by someone with nothing riding on it? | Self-reported — checked by the team it flatters. |
| A named owner | Who can be asked, and who can restate? | Unowned — nobody can be asked to defend it. |
Where decisions are executed by software rather than people, the same discipline extends one step: a decision record — what was known at the time, what alternatives were considered, what outcome was predicted against what actually happened — is the only thing that separates a sound decision from a lucky one. An outcome number cannot tell those apart; it reads the ratio at the end.
Adding reports never widens this panel. It is the one axis that only moves when somebody rules on a definition.
The two disciplines are routinely confused, and they buy differently. Enterprise Data Collaboration owns the plumbing — the clean room, the cloud estate, the BI layer, the agent-ready data. This playbook owns the semantics sitting on top of that plumbing: what the fields mean, whose definition wins, and what has to happen before a number changes.
Where the data lives, how it moves, who may join it to whose, and what the machine can read. Pipes, permissions, platforms.
What the number means, who is allowed to change that, what triggers a restatement, and which number a board may act on. Definitions, authority, record.
Both are real work and neither substitutes for the other. Perfect plumbing with ungoverned semantics produces faster disagreement. Governed semantics on broken plumbing produces a definition nobody can compute.
| Function | Governance layer | The question it answers |
|---|---|---|
| Finance | Publication + attestation | Can this number leave the building? |
| Data platform | Instrumentation + computation | Can it be rebuilt from source, by anyone? |
| Product & operations | Definition | Does the wording still describe what happens? |
| Internal audit / risk | Attestation | Would this survive an outside examiner? |
| CEO & board | The full system | Which number are we actually deciding on? |
The seat accountable for what a number means — and for what happens when it changes — is measurement governance.
The work is not a policy document. It is an operating system a leadership team can run — ten artifacts, each with a clear owner and a clear reason to exist.
What Every metric currently in use, with the pairs that answer the same question a different way named explicitly.
Who uses it CFO · CDO · Analytics
Why it matters Ends the argument about whether there is a problem by showing where two defensible numbers already disagree.
What One written definition per metric, with an owner, traceable lineage and a dated version.
Who uses it Finance · Data platform
Why it matters Turns a shared metric name into one number every consumer reads rather than redefines.
What Per metric family: who owns the definition, who may veto a change, who is consulted, who has no standing.
Who uses it Exec team · Data governance
Why it matters Makes definitional authority an assignment rather than a habit.
What The five gates a definition change clears, and the version discipline that retires rather than overwrites.
Who uses it Data governance · Owners
Why it matters Stops a dashboard filter edit from silently repricing comp plans and forecasts.
What The materiality threshold, the clock, the signature, and the notice list — set before the error.
Who uses it CFO · Audit committee
Why it matters Takes the disclosure decision away from whoever is most embarrassed by it.
What Which layer of proof each number carries, and which decision that layer was bought for.
Who uses it Finance · Insights
Why it matters Stops both kinds of waste: unproven numbers carrying big calls, and expensive proof on reversible ones.
What For each governed metric, what evidence would show it is wrong, and who is allowed to produce it.
Who uses it Analytics · Internal audit
Why it matters Gives a challenge somewhere to land, instead of ending in whose deck is louder.
What The narrow, named set of numbers a board may act on, each owned, versioned and restatable.
Who uses it CEO · CFO · Board
Why it matters Replaces the appendix with a set that can be defended line by line.
What Where an observation is unavailable, which substitute stands in its place and on whose authority.
Who uses it Data platform · Legal
Why it matters Keeps the metric name honest when what sits underneath it has quietly changed.
What The review cadence, the re-examination clock, and the standing agenda item that keeps the registry current.
Who uses it CDO · CFO
Why it matters Makes governance a running system rather than a project that shipped once.
The order is load-bearing. Nothing downstream is governable until a definition has an owner, so the track runs from inventory to published set — and each phase spends the authority the phase before it established. That is why the number gets narrower as the track runs, not wider.
Phase one rules on nothing. It only proves the problem exists, by naming the pairs that already answer the same question two ways.
Strip the model to what leadership actually has to answer. Measurement governance exists to settle five questions a board cannot delegate to a dashboard.
If the executive team cannot answer these five the same way, the company has a definitional-authority gap — not a reporting one.
The same argument, framed for the three seats that fund it. Lift a paragraph straight into a board memo, a finance review, or a data operating plan.
We produce more reporting every quarter and the number we actually decide on is no stronger than it was two years ago, because those are different axes. Measurement governance assigns definitional authority — one wording, one owner, one place a change is ruled on — and publishes a narrow board-grade set the company can defend line by line. It does not add a dashboard. It decides which of the ones we have counts.
Every number that leaves this building is a claim we will be asked to stand behind, and today most of them have no named owner, no version history, and no agreed rule for what happens when one is wrong. Measurement governance puts definitions under change control, sets the restatement policy before the miss rather than during it, and sizes the proof we buy to the decisions the numbers actually carry — so the first challenge from someone who did not want the answer is survivable.
The platform is not the problem. Instrumentation and definitions are usually versioned already; computation, publication and attestation are not, and the review always enters at the top. Measurement governance governs the three layers above the ones you control, assigns a veto where a change would make a downstream system silently wrong, and makes lineage a requirement of the record rather than a favour analysts do on request.
Market references last validated: September 12, 2026. Revalidate before pitch use.Sources: metric governance and evidence-standards practice; vendor-neutral, no client or platform-specific claims.
It is measurement governance — canonical definitions, named owners, change control, a restatement policy agreed before the miss, and an evaluation stack sized to the decisions the numbers actually carry. One narrow board-grade set, and a record that says who decided.
Ask about the essays, frameworks, playbooks, or how to work with Evgeny.