Six stages, one governed outcome
Structured, expert-led, shaped around your obligations.
Understand how you govern today
We map your change operating model, your obligations and the people accountable — then agree scope and success criteria in writing before anything is configured.
Change operating model mapped · Obligations in scope — s.166, CPS 230, DORA · Important business services identified · Scope and success criteria agreed
Metabole shaped to your model
Configuration, not customisation. Your register, gates, approvals and risk scoring are set up the way you already run them — so the platform recognises your governance on day one.
Service Register and important business services · Gate model G0–G5 — hard/soft, evidence · Approval workflows and accountable roles · Risk scoring and regime mapping
Connected, and in your region
Identity first, then your key systems and record sources — hosted in your data region. It sits alongside your stack rather than replacing it.
Single sign-on and provisioning (SSO / SCIM) · Secure API connections to key systems · Document and record sources · Data residency — UK, AU or EU
Validated against how you work
Your team tests the configuration against real scenarios. The governed loop is signed off because it matches practice — not because it matches the diagram.
Reference and in-flight change migrated · Scenario-based user acceptance testing · Configuration refined with your team · Written sign-off before go-live
A controlled go-live
Accountable roles are trained first, then end users. Playbooks are handed over and go-live is controlled, with early-life support close at hand.
Role-based training, accountable roles first · End-user enablement · Governance playbooks handed over · Controlled go-live with hypercare
Governance sustained, not shipped
We review adoption, refine the configuration against what the record shows, and hand you into ongoing Success & Support — so governance is maintained, not completed.
Adoption review · Configuration refinements · Handover to Success & Support · Governance sustained beyond the programme
A system of record beside your environment
Access and provisioning stay governed where they already are.
Delivery tooling and document sources you run today.
The governed loop, and the record it leaves
Gates, evidence and approvals in one place — hosted in your data region.
Alongside your stack, not instead of it
Your identity provider governs access and provisioning from the first login. No parallel user list.
A documented, secure API moves records and evidence between systems rather than re-keying them.
Hosted in UK, AU or EU — residency is answered by the deployment, not a caveat.
Configured to the infrastructure you run today. No rip-and-replace, no freeze on delivery.
A delivery model you can hold us to
Indicatively 8–14 weeks from kickoff to go-live, depending on scope.
Ready to get governed?
Bring your obligations and your operating model. We’ll show you the state you’d be in — and how we get you there.