Website Strategy & Architecture

Website Governance That Scales: Roles & Workflows

Jay Omanson

Website governance is the difference between a site that stays clean and consistent and one that slowly turns into a patchwork of “quick updates” from well-meaning teams. If more than one person can touch your CMS, you’ve probably seen it happen: marketing wants to move fast, departments want to own their pages, legal wants a look before anything risky goes live, and IT would love fewer late-night surprises.

You do not need a heavy rulebook to fix that. You need a few clear decisions, baked into how your site actually runs: who owns what, what approvals are required, and what “ready to publish” means in your world. Below is the approach we recommend to 10 Pound Gorilla clients who want speed without sacrificing quality, accessibility and compliance, and security.

Website governance: what it covers (and what it should never become)

Think of website governance as the operating system for your website content. It defines how pages are created, reviewed, approved, published, updated, and retired. It also makes ownership visible, so you are not guessing who is responsible for that outdated PDF or that events page from 2019.

What it should not be is a binder of rules that nobody reads after kickoff. Governance works best when it shows up inside the day-to-day tools your team uses, especially your roles, permissions, and workflow steps. Brightspot’s overview of governance models makes a simple point that holds up in the real world: teams move faster when ownership, approvals, and compliance expectations are clear and consistently enforced in the CMS rather than managed through side conversations and spreadsheets. You can read their perspective at Brightspot.

Pick a website governance model you can actually live with

Your governance model is basically how you distribute publishing authority. A model that looks great on an org chart can fall apart when it meets the reality of busy subject matter experts and tight timelines. Hannon Hill outlines three common models that most organizations end up choosing from, and their breakdown is a useful way to sanity-check your own setup. You can find it at Hannon Hill.

Most teams land in one of these governance models:

  • Centralized: One team controls publishing. You get consistency, but your web team becomes the bottleneck as requests pile up.
  • Decentralized: Departments publish their own content. You get speed, but quality and voice can drift, and duplicate pages multiply.
  • Hybrid: Departments draft and maintain their sections, while a central web team provides standards and final approval for higher-risk or higher-visibility content.

If you are growing, hybrid is usually the best fit. It lets the people closest to the work write the content, and it gives you a safety net for brand consistency, navigation discipline, and accessibility and compliance checks. It also keeps your “global” areas from getting accidentally edited by someone who only meant to update one page.

 

Website governance lives or dies on CMS roles and permissions

You can have the nicest governance doc in the world, but if your CMS permissions say “everyone can publish everything,” you are going to get chaos. Roles and permissions are where governance becomes real.

A practical way to think about permissions is in two dimensions:

  • What actions can someone take? Draft, edit, approve, publish, manage users, change site settings.
  • Where can they do it? A section, a department area, a region, or the whole site.

That two-part view is echoed by EnterpriseCMS.org’s guidance on defining CMS permissions and ownership. Their resources are worth a read at EnterpriseCMS.org, especially if you are dealing with lots of contributors and frequent staff changes.

Roles you can map to almost any CMS (including DNN and WordPress):

  • Content Contributor: Creates and edits drafts in assigned sections, but cannot publish.
  • Editor/Reviewer: Checks clarity, accuracy, SEO basics, and structure. Approves or sends back for changes.
  • Publisher: Pushes content live within defined sections and confirms it meets the checklist.
  • Administrator: Manages users, permissions, templates/components, and workflow configuration.

Then comes the part that saves you from permission sprawl: domain-based access. Your HR team might publish Careers content, but not touch Product pages. A regional office can manage local location pages, but not edit global navigation. That is how you keep autonomy without letting one well-intentioned edit ripple across the entire site.

Two habits that keep permissions from getting messy:

  • Quarterly access checks: Review who has publish and admin rights. Remove old access when roles change or contractors roll off.
  • Separate automation from people: If you have integrations or scheduled publishing jobs, use dedicated tokens or service accounts so human access stays limited and auditable.

Build a website governance workflow that matches real life

A “Draft to Publish” workflow works fine until you add legal review, accessibility and compliance requirements, multiple approvers, and sections with different levels of risk. At that point, a simple workflow becomes a guessing game, and your team starts routing approvals through email because it feels faster.

Aprimo frames content governance as the system that guides how you create, manage, distribute, and retire content. Retirement is the part most teams forget, and it is usually why websites feel bloated over time. Their thinking is useful background at Aprimo.

Workflow states that work well for growing teams:

  1. Draft: A contributor builds content using approved components and guidelines.
  2. Editorial Review: An editor checks clarity, accuracy, SEO basics, and whether the page fits the site structure.
  3. Accessibility and Compliance Review: You confirm readability, headings, link text, image alt text, and any required standards. If you need a solid baseline for what to check, 10 Pound Gorilla’s Web Accessibility Services page lays out what accessibility and compliance should cover across design, code, and content.
  4. Legal/Policy Review (only when needed): Required for regulated claims, disclosures, privacy language, healthcare content, or public-sector updates.
  5. Final Approval: A publisher checks links, formatting, placement, and readiness.
  6. Published: The page goes live with an owner, a review date, and a reason it exists.
  7. Review Due / Expired: The page comes back for refresh, consolidation, or retirement.

The trick is to make the workflow flexible without making it vague. If a page does not need legal review, your workflow should not force it through legal. If it does need legal, you should know exactly what “approved” means and who can sign off.

Make website governance easier by encoding it into the CMS

If governance only lives in documentation, it relies on memory and good intentions. That is not a strategy. The more effective approach is to build governance into your CMS so it nudges people toward the right choices.

Governance rules that belong in the CMS, not in email threads:

  • Workflow gates: Require approvals before publishing in high-risk areas.
  • Structured fields: Store page owner, review date, audience, and intent as fields, not buried in body copy.
  • Reusable components: Use consistent building blocks so pages stay on brand and design drift is harder to introduce.
  • Section-based permissions: Let teams move quickly inside their area while protecting global elements.

This is where platform configuration matters. If you are on DotNetNuke (DNN) or WordPress, you can absolutely build a governance-friendly setup, but it has to be intentional. For DNN, we start with the platform strengths and governance needs first. If your organization is exploring that route, DotNetNuke (DNN) is outlined at 10 Pound Gorilla’s DNN overview. And if WordPress is your standard, the same thinking applies: define roles, sections, and workflow before you hand out publish access.

Fresh From the Jungle Each Month

Get our best insights delivered once a month — no monkey business.

 

Where website governance breaks down (and what to do instead)

Most governance problems are not mysterious. They follow the same patterns, especially right after a re-org, a site redesign, or a growth spurt.

Common breakdowns to watch for:

  • Too many publishers: If everyone can publish, accountability disappears. Keep publish rights limited and scoped by section.
  • Unclear ownership: If nobody owns a section, it will go stale. Assign owners and review dates.
  • Email as workflow: Email loses history and creates inconsistency. Put approvals and states into the CMS.
  • No measurement: If you cannot see whether governance is helping, it will feel like busywork.

Simple metrics worth checking each quarter:

  • Time to publish: Median time from draft to published for standard updates.
  • Rework rate: How often pages bounce back for the same issues.
  • Stale content rate: Percentage of pages past their review date.
  • Accessibility issue volume: Issues found during QA, especially repeated patterns that point to training gaps or missing components.

If your governance includes accessibility and compliance checks, keep them practical. You want a repeatable checklist and a workflow step that makes it routine. A helpful starting point is 10 Pound Gorilla’s WCAG 2.2 audit checklist, which breaks testing into specific items your team can apply during reviews and release QA.

How a Structured content system makes website governance easier to scale

If your editors can build pages out of consistent building blocks, governance gets easier overnight. You are no longer relying on every contributor to remember layout rules, heading structure, or brand patterns. The system quietly does some of that work for them.

That is the idea behind a structured content system: component-based content that stays consistent while still giving your teams room to publish. It also helps SEO and UX because your headings, navigation patterns, and page layouts behave predictably across the site.

If you want a real example of what that looks like, the Structured Content System case study shows how modular content architecture can reduce design drift while supporting a large editor group.

FAQ: Website governance, roles, and workflows

What is the difference between website governance and content governance?

Website governance is the bigger umbrella. It includes content governance, plus things like templates and components, integrations, analytics ownership, security and access rules, and how the site is maintained over time. Content governance focuses on how content is created, reviewed, published, and retired.

Which website governance model works best for growing teams?

Hybrid is often the most practical. Your departments can draft and maintain what they know best, and a central web team sets standards and handles approvals for higher-risk or high-visibility areas. That balance usually protects brand consistency and accessibility and compliance without slowing you down.

How many people should have publishing permissions?

Usually fewer than you think. Start with a small set of publishers, limit their access by section, and expand only when teams show they can follow the workflow. Then review access quarterly so “temporary” permissions do not become permanent by accident.

Do you need legal review for every page?

No. Your workflow should match risk. Define which content types require legal review, such as regulated claims, disclosures, policy updates, or privacy language. Let lower-risk updates move through a faster path.

How do you keep content from going stale?

Give every page a clear owner and a review date, and treat “Review Due” as a real workflow state. Governance is not just about publishing new pages. It is also about updating, consolidating, and retiring content so your site stays trustworthy.

Conclusion: make website governance your advantage as you grow

As your organization adds teams, regions, and subject matter experts, website governance keeps the site coherent and safe. Clear roles and permissions, a workflow that matches how your teams work, and structure inside the CMS let you publish faster without letting quality slip.

If you want a second set of eyes on your current setup, or you are planning a rebuild where governance needs to be designed in from day one, we can help you map roles, workflow states, and a structured content system that fits your reality. If you want to talk through options and scope in a No Surprises kind of way, start with the 10 Pound Gorilla contact page.