Microsoft Project Online retires September 30, 2026, migrate to a modern platform before it's too late.Start migration
ENTERPRISE+ feature, built for regulated PMOs

Enterprise project governance

Twelve-stage proposal pipeline with multi-reviewer gates, weighted evaluation criteria, Change Control Board workflow, and an audit trail that holds up under SOX, HIPAA, and federal review. Built for the PMOs that actually need governance, not the ones that think they do.

The governance pipeline: proposals move through staged gates with multi-reviewer approvals and weighted scoring.

The 12-stage pipeline

Every proposal moves through a canonical state machine. Sponsors see where they are; reviewers see what's pending; PMOs get a defensible audit trail.

A proposal card moves across a governance board from Proposals to Under Review; a gate panel shows three designated reviewers scoring strategic alignment, business value and feasibility, each weighted, with a weighted total and an approval tick per reviewer; when all three approve, the card moves to Business Case and the sponsor's inbox receives the decision; two later gates pass the same way; at Approved a project is created from the proposal, and a history strip records every review and stage change.An animated diagram. A proposal through the gates, scored, approved, and turned into a project, with every step on the record.GOVERNANCE PIPELINEProposalsUnder ReviewBusiness CasePlanningApprovedActiveSpring ConferenceSarah Chen · 12 weeksPROPOSAL REVIEW · GATE 1 OF 33 designated reviewersReviewerStrategic alignment ×2Business value ×1.5Feasibility ×1WeightedTom Bennett81Mira Okafor76Priya Raman880 of 3 approved. Waiting on the panel.1 of 3 approved. Still pending.2 of 3 approved. Still pending.3 of 3 approved. Moves to Business Case.one rejection ends itGate 2 · Business Case Review · not yet reachedGate 3 · Plan Review · not yet reachedGate 2 · Business Case Review · its own reviewers and criteria · 3 of 3 approvedGate 3 · Plan Review · 3 of 3 approved · the proposal is ApprovedSARAH'S INBOXGate review completed for "Spring Conference"Approved at the Proposal Review gate by Priya Raman.It has advanced to Business Case.Gate review completed for "Spring Conference"Approved. Project "Spring Conference" has beencreated. The proposal advances to Approved.PROJECTSpring ConferenceOwner Sarah Chen · 12 weeks from todayCreated from the proposalGovernedHISTORYTue 14:02 Tom Bennett approved · Proposal Review · weighted 81Tue 14:15 Mira Okafor approved · Proposal Review · weighted 76Tue 14:31 Priya Raman approved · Proposal Review · weighted 88Tue 14:31 Stage · Proposal Review to Business CaseFri 09:10 Stage · Plan Review to ApprovedFri 09:10 Project created · Spring Conference
  1. Proposals
    Before the first gate
    1. 1

      Draft

      The sponsor writes it up: title, the case in outline, a first estimate.

    2. 2

      Submitted

      Handed in. Submitting sends it straight into the first gate, with no separate hand-off step.

  2. Under Review
    Gate 1
    1. 3

      Proposal Review

      Gate 1

      A designated panel scores weighted criteria. One rejection ends it; every approval moves it on.

  3. Business Case
    Gate 2
    1. 4

      Business Case

      Back with the sponsor for the full case: benefits, justification, budget and duration.

    2. 5

      Business Case Review

      Gate 2

      A second panel with its own criteria. Financial rigour, risk and the resource plan are the defaults.

  4. Planning
    Gate 3
    1. 6

      Planning

      The delivery plan: schedule, resourcing, risks, and who will own the project.

    2. 7

      Plan Review

      Gate 3

      The last gate before execution. Schedule credibility, architecture and change management by default.

  5. Approved
    Through every gate
    1. 8

      Approved

      The project is created from the proposal, at the gate you configure, and the sponsor is told.

  6. Active
    In delivery
    1. 9

      Active

      Linked to its project and on the portfolio dashboards, with the proposal as its origin.

  7. Closed
    Three ways out
    1. 10

      Completed

      Delivered. A benefits review checks what was realised against the case.

    2. 11

      On Hold

      Parked. Unhold returns it to the stage it left, not to the start.

    3. 12

      Rejected

      Did not pass a gate. The decision, the reviewer and the reason stay on the record.

Before the first gate

Where a proposal comes from

A pipeline is only as good as what enters it. Three doors lead to Draft, and two of them cost the person on the other side nothing but a sentence.

All plans

An idea, captured in seconds

Write it down without picking a project. It stays private until you share it. Ask for AI feedback and it comes back graded against the company's goals: a critique, the questions to answer, the risks, and a recommended route. Promote it when it is ready, to a task assigned to you if it is small, or to a proposal that always lands in Draft, so an idea can never skip a gate.

Forms on Pro and above

A public intake form

A form anyone can submit, with no account, behind an access password if you want one. Submissions land in one view, and one click turns a submission into a proposal in Draft. Convert the same submission twice and you get the same proposal back, not a duplicate.

Enterprise

A sponsor, writing it directly

The proposal form: title, business case, priority, risk level, budget, department and strategic alignment. Visible to the sponsor alone until it is submitted, and from that moment every transition is in the audit log.

The third door, the proposal form itself: priority, risk, budget, sponsor and who will own the project, captured before the first gate.

Whichever door it came through, the record starts at Draft, and from there the twelve stages above and the audit log apply to all of them alike.

Six governance capabilities

Specific, scoped, audit-friendly. No "configurable workflows" hand-waving.

Multi-reviewer gates with quorum

Designate per-gate reviewer panels (PROPOSAL_REVIEW, BUSINESS_CASE_REVIEW, PLAN_REVIEW). Auto-creates ProposalGateApproval rows on review-stage entry. Quorum logic: any single rejection rejects the proposal; all approvals advance it; otherwise stays pending.

Per-gate evaluation criteria

Configure weighted scoring criteria per gate: strategic fit, business value, risk profile, resource availability. Org-scoped overrides on top of global defaults. Reviewers score each criterion; the platform computes the weighted total.

Role-based reviewer access

Designated MEMBER-role gate reviewers can submit reviews even without org-level governance permission, scoped to specific gates. Removes the "give everyone admin so they can review proposals" anti-pattern.

Change Control Board (CCB)

Formal scope/schedule/budget change request workflow per project. CRs go through review with designated CCB members, status tracking (DRAFT → SUBMITTED → UNDER_REVIEW → APPROVED/REJECTED → IMPLEMENTED). Audit trail preserved.

On-hold preservation

Putting a proposal on hold preserves the previous stage. Unhold restores it, not a hard-coded fallback to SUBMITTED. Important for regulated industries where stage transitions must be reversible without losing context.

Sponsor notifications + audit

Sponsors notified on every gate decision, stage transition, and auto-project creation. Every transition writes an AuditLog row with actor, timestamp, before/after state, and details. AuditLog retention follows the per-org RetentionPolicy.

Regulated-industry posture

Three contexts where the governance + audit + retention stack actually has to hold up.

Finance / SOX

Stage transitions are auditable with before-and-after diffs. Multi-reviewer gates enforce segregation of duties. CCB workflow gives a defensible change-control trail. Audit retention configurable to 7+ years on ENTERPRISE+.

Healthcare / HIPAA

Per-tenant data isolation. Audit log captures every access to PHI-adjacent records. Designated reviewer access means clinical staff can review without becoming admins (and gaining broader access).

Federal PMOs / FedRAMP-style

Self-host on ENTERPRISE_PLUS for sensitive workloads. Audit log + SCIM provisioning + IP allowlist + SAML SSO meet typical federal evidence requirements. Customer-managed encryption keys (CMK) available at the highest tier.

SOC 2 is in progress and Onplana is not yet certified. Retention configurations and per-tier feature flags are documented in /security. IT-admin setup guides for the most-installed IdP: Microsoft Entra SSO · SCIM provisioning.

Migrating Project Online governance?

Project Online retires September 30, 2026, taking SharePoint workflow-based governance with it. Onplana's 12-stage pipeline + CCB workflow is the closest direct replacement for organisations running formal proposal-to-project governance. Migration imports existing in-flight projects; new proposals enter the pipeline at Draft.

Frequently asked questions

Where do proposals come from?
Three places, and all three land in Draft. A sponsor can write one directly. A public intake form can collect requests from anyone, with no account, and one click converts a submission into a proposal. And an idea captured anywhere in Onplana can be promoted into one, after AI feedback graded against your goals if you want it. Ideas are on every plan, intake forms on Pro and above, and the pipeline they feed is Enterprise.
What plan tier do I need for the 12-stage pipeline?
ENTERPRISE plan minimum. Governance is the most capability-heavy feature in Onplana, it's not a starter capability. Mid-tier plans (PRO, BUSINESS) get the proposal model itself but not the full 12-stage workflow with multi-reviewer gates and audit trail. ENTERPRISE_PLUS adds customer-managed keys and self-host options on top.
Can I customise the 12 stages or the gate criteria?
The 12 stages are fixed (DRAFT through REJECTED), they're the canonical state machine. Within those stages: per-gate evaluation criteria are fully configurable per org, and per-gate reviewer panels are configurable. The CCB workflow has its own DRAFT → SUBMITTED → ... state machine that's separately configurable. The structure is opinionated; the contents are yours.
How does multi-reviewer quorum logic actually work?
On entry to a review stage, ProposalGateApproval rows are auto-created, one per designated reviewer. Each reviewer submits an APPROVED or REJECTED decision. Logic: (1) any single REJECTED → proposal rejected; (2) all APPROVED → proposal advances; (3) otherwise → stays at current stage with quorumPending: true in the API response. Reviewers can change their mind before quorum is reached.
Does the audit log capture enough for SOX / HIPAA?
Yes for SOX and most HIPAA contexts, with caveats. Onplana writes AuditLog rows on every governance state transition with actor identity, timestamp, before/after diff, and request method/path. Retention follows the per-org RetentionPolicy (presets: STANDARD / GDPR / HIPAA / FINRA / SOC 2 / CUSTOM). For regulated workloads we recommend the HIPAA preset (6 years user, forever org, forever audit) and ENTERPRISE_PLUS self-host.
Can governance and CCB run on the same project?
Yes, they're separate workflows with separate state machines. Governance gates new proposals from idea to project creation. CCB handles changes to in-flight projects (scope, schedule, budget). Both write to the audit log, both have designated reviewer panels, both are gated to ENTERPRISE+.
How is "designated reviewer" different from "ADMIN role"?
Pre-2026 Onplana required org-level governance permission to submit gate reviews, typically MANAGER or ADMIN role. That bundled too much: clinical reviewers, finance reviewers, and security reviewers don't need broader admin access. Designated reviewers fix this: a MEMBER-role user can be designated for specific gates and submit reviews scoped to those gates only, without becoming an org admin. Least-privilege governance.

Talk to us about ENTERPRISE governance

ENTERPRISE plan + walkthrough. We'll map your current governance model to the 12-stage pipeline before you commit.