Product1 publisher3 min readPublished
Written governance is not a mechanism: CNCF's 72-project review makes the case
Multi-org maintainers at sandbox entry track a 2.07x graduation rate, and every graduated project that later concentrated lacked org-balance voting at incubation.
The Product Desk · Product desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- CNCF published governance guidance based on governance reviews across 72 graduated, incubating and archived projects, capturing patterns as guidance for projects choosing or evolving governance structure.
- Projects with maintainers from multiple organizations at sandbox entry graduate at 2.07x the rate of single-org projects (59.1% vs 28.6%).
- Projects with steering committees or org-balanced voting sustain maintainer diversity longer than those without structural mechanisms.
- Documentation without structural mechanisms often fails to prevent concentration; multiple projects with well-written governance docs experienced maintainer concentration because their governance lacked org-balance voting or steering committee limits.
- 20% of graduated projects now show post-graduation governance concentration, all lacking org-balance mechanisms at incubation.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
CNCF has published governance guidance built on reviews of 72 graduated, incubating and archived projects, and the finding worth arguing about is that a well-written governance document does very little on its own [1][4]. Projects that entered the sandbox with maintainers from more than one organisation graduated at 2.07 times the rate of single-org projects, 59.1% against 28.6% [2], a spread of 30.5 percentage points [1].
The negative results are the useful part. CNCF reports that documentation without structural mechanisms often fails to prevent concentration, and that multiple projects with well-written governance docs concentrated anyway because their governance lacked org-balance voting or steering committee limits [4]. Twenty percent of graduated projects now show post-graduation governance concentration, and all of them lacked org-balance mechanisms at incubation [5]. One archived incubating project had org diversity rules on its governance committee but not on its maintainer body [6]. CNCF's reading is that org-balance mechanisms need to cover where the work happens, not just the governance layer [7]. That is a specific and checkable claim about placement: a company cap on a nine-person committee does nothing if one employer holds the commit bits.
The guidance maps three templates from the CNCF project template repository onto project archetypes [8]. The Maintainer Council is a self-selecting group in which the people who write the code are the people who govern, with lazy consensus as the default and formal votes reserved for disagreements or governance changes [9]; CNCF scopes it to bounded projects with 3 to 10 active maintainers who already talk to each other [10]. Its key elements are mundane and mostly clerical: a MAINTAINERS file carrying names, affiliations and domains, a documented process for adding and removing maintainers including for inactivity, emeritus status, and defined voting thresholds for governance changes [11]. The stated trigger for evolving out of it is a single organisation coming to dominate the maintainer list through hiring, acquisition or attrition of external contributors, at which point CNCF advises adding org-balanced voting or moving to an elected steering committee [12].
The Elected Steering Committee model puts strategy with an elected body and delegates technical work to working groups or SIGs, using elections for accountability and term limits plus company representation limits for diversity of perspective [13]. The concrete elements are term limits of typically one to two years, caps such as no more than one or two members per organisation, a documented removal process that covers non-performance during a term, and public meeting notes and decision records [14]. Naming varies: some projects call it a TSC or Governance Committee, and some run both an administrative steering committee and a technical one [15]. CNCF attributes the correlation with sustained diversity to the separation of governance from execution [16].
Two cautions. The review also says contributor count alone does not predict project health, which cuts against the headcount metrics most projects report [17]. And these are rates, not experiments: the data section gives 59.1%, 28.6% and 20% without the number of projects behind each [18], so multi-org sandbox entry may be a proxy for having two employers willing to fund the work rather than a cause of graduation. The mechanism argument stands better on the concentration finding, where the failure cases are named as structural gaps at a specific stage [5].
Watch whether these recommendations move into what CNCF requires at a maturity level, since the post explicitly separates requirements from what the data recommends [19]. Watch also whether projects respond by putting org caps on maintainer lists rather than only on committees [7], and whether the 20% figure moves if the review is repeated [5].