The redesigned Microsoft Purview has reached general availability, and the phrase Microsoft keeps attaching to it is "business-led data governance." I want to take that phrase seriously, because underneath the marketing there's a genuinely good idea — and a genuinely common way to get it wrong. The idea is right. Whether your organisation benefits from it depends entirely on whether you also transfer the thing that makes it work, which most transfers of this kind quietly forget to include.
Let me start with why "business-led" is the correct instinct.
The good idea inside the slogan
For most of its history, data governance has been an IT function. The people who owned the catalogue, set the policies, and maintained the definitions sat in a central technical team — usually far from the business context that gives data its meaning. And that arrangement has a structural flaw that no amount of tooling fixes: the people who understand what the data means are almost never the people who were made responsible for governing it.
The finance team knows what "revenue" should mean. The clinical team knows which patient fields are genuinely sensitive and which just look scary. The sales team knows which "customer" record is the real one. That knowledge lives in the business domains, not in central IT — and yet governance kept being done to the domains by a technical team translating at second hand. The result was governance that was always slightly wrong, always out of date, and always resented as something imposed from outside.
"Business-led" governance is the move to fix that: put the governance of a data domain in the hands of the people who actually understand that domain. Purview's GA leans into this — domain-oriented structures, business-friendly experiences, Copilot-assisted guidance to lower the technical bar, catalogue and lineage surfaced for domain owners rather than only for specialists. As a direction, I think it's simply correct. Governance should be led by the people who know what the data means. Full stop.
The hard part everyone forgets to transfer
Here's where it goes wrong, and it goes wrong the same way nearly every time. Organisations hear "business-led governance," hand the business domain a governance tool, and consider the job done. They've transferred the software. They have not transferred the three things that actually make governance happen:
- Time. A domain expert asked to also own data governance, on top of their actual job, with no time allocated for it, will do exactly as much governance as that allocation implies: none. "Business-led" without a real, funded slice of someone's week is just a nicer word for "unfunded."
- Accountability. For governance to be led by the business, someone in the business has to be genuinely accountable for it — named, expected to deliver, asked about it by their own leadership. Handing the tool to a domain without making anyone answerable just relocates the orphan. The data is still nobody's, now in a better interface.
- Capability. Copilot and a friendlier UI lower the technical barrier, and that's real. But leading governance still takes judgement about what matters, what's sensitive, and what your words should mean — and that capability has to be supported and developed, not assumed to arrive with the licence.
Transfer the tool without those three, and "business-led governance" becomes a way for central IT to stop doing governance without anyone starting to do it instead. Which is arguably worse than the old flawed model, because at least the old model had someone doing it badly rather than no one doing it at all.
"Business-led" is not a feature you switch on. It's an operating model you fund. The software is the easy 20%; the time, accountability, and capability are the 80% that decides whether it works.
How to actually make it land
So if you're looking at the Purview GA and the business-led promise and wondering how to get the good version rather than the orphaned one, the work is organisational, not technical:
Pick one business domain that genuinely matters and set it up properly as the template. Name a real, willing owner in that domain. Get their leadership to make them genuinely accountable — governance of this domain is now part of what they're measured on, not a favour. Allocate actual time. Use Purview's friendlier experience and Copilot assistance to make that time productive rather than spent fighting tooling. And only once that one domain is working — owned, resourced, accountable — use it as the proof and the pattern to bring the next domain across.
What I'd avoid is the launch-day temptation the GA invites: rolling "business-led governance" out across every domain at once by distributing licences and a training deck, and mistaking that distribution for a transfer of responsibility. The tool will deploy in a week. The operating model takes far longer, because you're changing who's accountable for something, and that's a leadership act, not an IT rollout.
The verdict
I'm genuinely positive about this release, and I want to be clear about that, because my caution can read as cynicism and it isn't. Purview's GA points governance in the right direction — toward the people who understand the data — and gives them better, more approachable tools to do it with. That's a real step forward and I'm glad of it.
But the release can only offer the tool. Whether "business-led" becomes a genuine improvement or an elegant way to drop the ball depends on a decision no product can make for you: whether your organisation is willing to give the business domains the time, the accountability, and the support to actually lead. Get that right and Purview's new era is real. Skip it, and you'll have bought a lovely governance platform and quietly arranged for no one to be responsible for using it.