Enterprise project governance
Twelve-stage proposal pipeline with multi-reviewer gates, weighted evaluation criteria, Change Control Board workflow, and an audit trail that holds up under SOX, HIPAA, and federal review. Built for the PMOs that actually need governance, not the ones that think they do.
The 12-stage pipeline
Every proposal moves through a canonical state machine. Sponsors see where they are; reviewers see what's pending; PMOs get a defensible audit trail.
- ProposalsBefore the first gate
- 1
Draft
The sponsor writes it up: title, the case in outline, a first estimate.
- 2
Submitted
Handed in. Submitting sends it straight into the first gate, with no separate hand-off step.
- Under ReviewGate 1
- 3
Proposal Review
Gate 1A designated panel scores weighted criteria. One rejection ends it; every approval moves it on.
- Business CaseGate 2
- 4
Business Case
Back with the sponsor for the full case: benefits, justification, budget and duration.
- 5
Business Case Review
Gate 2A second panel with its own criteria. Financial rigour, risk and the resource plan are the defaults.
- PlanningGate 3
- 6
Planning
The delivery plan: schedule, resourcing, risks, and who will own the project.
- 7
Plan Review
Gate 3The last gate before execution. Schedule credibility, architecture and change management by default.
- ApprovedThrough every gate
- 8
Approved
The project is created from the proposal, at the gate you configure, and the sponsor is told.
- ActiveIn delivery
- 9
Active
Linked to its project and on the portfolio dashboards, with the proposal as its origin.
- ClosedThree ways out
- 10
Completed
Delivered. A benefits review checks what was realised against the case.
- 11
On Hold
Parked. Unhold returns it to the stage it left, not to the start.
- 12
Rejected
Did not pass a gate. The decision, the reviewer and the reason stay on the record.
Where a proposal comes from
A pipeline is only as good as what enters it. Three doors lead to Draft, and two of them cost the person on the other side nothing but a sentence.
An idea, captured in seconds
Write it down without picking a project. It stays private until you share it. Ask for AI feedback and it comes back graded against the company's goals: a critique, the questions to answer, the risks, and a recommended route. Promote it when it is ready, to a task assigned to you if it is small, or to a proposal that always lands in Draft, so an idea can never skip a gate.
A public intake form
A form anyone can submit, with no account, behind an access password if you want one. Submissions land in one view, and one click turns a submission into a proposal in Draft. Convert the same submission twice and you get the same proposal back, not a duplicate.
A sponsor, writing it directly
The proposal form: title, business case, priority, risk level, budget, department and strategic alignment. Visible to the sponsor alone until it is submitted, and from that moment every transition is in the audit log.
Whichever door it came through, the record starts at Draft, and from there the twelve stages above and the audit log apply to all of them alike.
Six governance capabilities
Specific, scoped, audit-friendly. No "configurable workflows" hand-waving.
Multi-reviewer gates with quorum
Designate per-gate reviewer panels (PROPOSAL_REVIEW, BUSINESS_CASE_REVIEW, PLAN_REVIEW). Auto-creates ProposalGateApproval rows on review-stage entry. Quorum logic: any single rejection rejects the proposal; all approvals advance it; otherwise stays pending.
Per-gate evaluation criteria
Configure weighted scoring criteria per gate: strategic fit, business value, risk profile, resource availability. Org-scoped overrides on top of global defaults. Reviewers score each criterion; the platform computes the weighted total.
Role-based reviewer access
Designated MEMBER-role gate reviewers can submit reviews even without org-level governance permission, scoped to specific gates. Removes the "give everyone admin so they can review proposals" anti-pattern.
Change Control Board (CCB)
Formal scope/schedule/budget change request workflow per project. CRs go through review with designated CCB members, status tracking (DRAFT → SUBMITTED → UNDER_REVIEW → APPROVED/REJECTED → IMPLEMENTED). Audit trail preserved.
On-hold preservation
Putting a proposal on hold preserves the previous stage. Unhold restores it, not a hard-coded fallback to SUBMITTED. Important for regulated industries where stage transitions must be reversible without losing context.
Sponsor notifications + audit
Sponsors notified on every gate decision, stage transition, and auto-project creation. Every transition writes an AuditLog row with actor, timestamp, before/after state, and details. AuditLog retention follows the per-org RetentionPolicy.
Regulated-industry posture
Three contexts where the governance + audit + retention stack actually has to hold up.
Finance / SOX
Stage transitions are auditable with before-and-after diffs. Multi-reviewer gates enforce segregation of duties. CCB workflow gives a defensible change-control trail. Audit retention configurable to 7+ years on ENTERPRISE+.
Healthcare / HIPAA
Per-tenant data isolation. Audit log captures every access to PHI-adjacent records. Designated reviewer access means clinical staff can review without becoming admins (and gaining broader access).
Federal PMOs / FedRAMP-style
Self-host on ENTERPRISE_PLUS for sensitive workloads. Audit log + SCIM provisioning + IP allowlist + SAML SSO meet typical federal evidence requirements. Customer-managed encryption keys (CMK) available at the highest tier.
SOC 2 is in progress and Onplana is not yet certified. Retention configurations and per-tier feature flags are documented in /security. IT-admin setup guides for the most-installed IdP: Microsoft Entra SSO · SCIM provisioning.
Migrating Project Online governance?
Project Online retires September 30, 2026, taking SharePoint workflow-based governance with it. Onplana's 12-stage pipeline + CCB workflow is the closest direct replacement for organisations running formal proposal-to-project governance. Migration imports existing in-flight projects; new proposals enter the pipeline at Draft.
Frequently asked questions
Where do proposals come from?▾
What plan tier do I need for the 12-stage pipeline?▾
Can I customise the 12 stages or the gate criteria?▾
How does multi-reviewer quorum logic actually work?▾
Does the audit log capture enough for SOX / HIPAA?▾
Can governance and CCB run on the same project?▾
How is "designated reviewer" different from "ADMIN role"?▾
Talk to us about ENTERPRISE governance
ENTERPRISE plan + walkthrough. We'll map your current governance model to the 12-stage pipeline before you commit.