Decision rights are the substance of governance. Not "the council governs customer data", but: who approves a new customer attribute, who approves a change to an existing definition, who grants access to it outside the domain, who accepts a quality tolerance, who declares an incident. Each of those is a distinct decision with a distinct decider, and writing them down is often the single highest-value week a governance program spends.

In practice. A one-page grid — decision down the side, role across the top, one A per row — is enough. The constraint that makes it useful is that every row has exactly one accountable party. Two A's in a row is an unresolved argument written down as if it were a design.

Where it goes wrong. Decision rights are documented as a RACI over activities rather than decisions, which produces a matrix where everyone is consulted on everything and nothing gets faster. The other failure is publishing the grid without telling anyone their name is on it.