The 20-Day Governance Build
One workspace for several entities, partners or departments. Every party sees only what it should, the rules are written down, and you hold the evidence before anyone asks for it.
Apply for a slot →A governed workspace, built and evidenced in twenty working days.
An isolation architecture across your entities, a written access model mapped to ISO 27001 Annex A controls, and the operating databases each party runs on.
An evidence pack per entity: access matrix, permission register, review procedure, offboarding runbook. Written so a partner, a DPO or an auditor can read it without you in the room.
The deposit, and only until day 10. If the architecture is not approved, it comes back. After that, three more guarantees below.
Why a normal build is not enough here
A ten-day build gives one team one workspace. The moment a second entity, a partner organization or a compliance question enters the picture, the problem changes shape.
- One wrong share exposes another entity's data. Teamspaces, guests and page-level sharing each have their own rules, and nobody has written down which one applies where.
- An enterprise client or investor sends a security questionnaire. "Who has access to our data and how is it reviewed?" has no answer yet, and the deal waits until it does.
- Seats and guests drift. People leave, contractors stay, and the invoice grows without anyone deciding it should.
- The person who set it up is the only one who understands it. If they are away, access requests stall and workarounds start.
How the twenty days run
Two calls from you, one gate on day 10, and a handover your team can run without me.
Who needs to see what, written down
One 90-minute call with you and whoever owns each entity or function. I inventory what exists today, who holds access, what the sensitive data is and where the boundaries between parties have to sit. Out of it comes a data classification and a draft access matrix, before anything is built.
The architecture you approve on day 10
- Isolation architecture. Which entities share a workspace and which do not, how teamspaces, groups and guests are used, and where synced or shared views are allowed.
- Access model mapped to ISO 27001 Annex A. Access control (5.15), identity management (5.16), access rights (5.18), privileged access (8.2) and information access restriction (8.3), each with a Notion setting behind it.
- A written architecture document you sign off on. Nothing is built at scale until you have approved it, and the balance is only due once you have.
The workspace, made to the approved design
- Operating databases per entity. Clients, projects, documents and tasks, with relations that stay inside the boundary they belong to.
- Permissions set and tested. Every role in the access matrix is tested with a real account, and the result is recorded in the evidence pack.
- Migration of what exists. Drive, SharePoint, email and half-built Notion, moved deliberately and classified on the way in.
- Automations for the repeating work, and a guest offboarding runbook so access ends when the engagement does.
Proof in hand, and a team that can run it
- The evidence pack. Access matrix, permission register, quarterly review procedure, offboarding runbook, audit log export procedure, and a partner-facing summary per entity.
- Two training sessions, recorded: one for admins, one for everyone else.
- Ninety days of support, including the first quarterly access review, run with you.
The day 10 gate
The balance is never due on trust. It is due on a document you have read and approved.
You read the architecture
Entity boundaries, the access matrix, the control mapping and the migration plan, in one document written for a non-technical owner.
You approve it, or you do not
Approved: the $10,000 balance is invoiced and the build starts on day 11. Not approved: the $2,500 deposit is refunded in full and you keep the document.
Nothing changes after the gate
The approved architecture is the scope. No change orders, no re-quote halfway through.
What the build contains
Priced as if each part were bought on its own, which is the honest way to see what $12,500 is buying.
| Isolation architecture across entities and partners | $6,000 |
| Access model mapped to ISO 27001 Annex A controls | $4,500 |
| Data classification and permission testing per role | $2,500 |
| The build | |
| Operating databases, views and automations per entity | $7,500 |
| Migration from Drive, SharePoint, email or existing Notion | $3,000 |
| Included at no extra cost | |
| Evidence pack and partner-facing summary per entity | $3,500 |
| Two recorded training sessions, admins and team | $1,200 |
| Ninety days of support and the first quarterly access review | $2,400 |
| Total value | |
What you are risking
Four guarantees, in writing before the deposit is paid.
Approved on day 10, or the deposit comes back
If you do not approve the architecture document on day 10, the $2,500 is refunded in full and you keep the document.
Every role tested, in writing
Each role in the access matrix is tested with a real account before handover, and the test record is in your evidence pack. If a test fails after handover, I fix it at no charge.
The evidence pack answers the questionnaire
If a partner, client or auditor asks an access question in the first 90 days that the pack does not answer, I write the answer and add it to the pack, at no charge.
No change orders
The approved architecture is the scope. The price does not move after day 10.
Two at a time. I run at most two Governance Builds in parallel so that twenty days means twenty days. If both slots are taken, the Fit Call tells you when the next one opens.
Why me
Access models are my day job, not a Notion feature
CISSP, CISA, CISM, CRISC, ISO 27001 Lead Implementer, 15+ years in technology risk and IT audit, most of it at EY. The control mapping in this build is the same work I do for regulated firms.
The only security credential in the certified Notion directory
Notion Certified Consultant, Notion Certified Admin, Service Specialist and Technical Specialist. Across the certified Notion consultant directory, no other consultant holds a security credential.
I build inside your workspace at no seat cost
As a registered Notion Consulting Partner I can be added without taking a paid seat, in every entity's workspace.
60+ engagements, 50+ countries, templates rated 4.92/5
Including multi-entity groups, agencies with client workspaces, and firms that had to answer an enterprise security questionnaire to close a deal.
Questions
Do we need one workspace or several?
That is the first decision the architecture makes, and it depends on how independent the entities are, who bills whom, and what has to be provably separated. Both answers are valid. You get the reasoning in writing on day 10.
Will this pass an ISO 27001 or SOC 2 audit?
Notion is one system inside your scope, not the whole audit. The access model and the evidence pack are written so the Notion part of the audit is answered with documents, not with a demo. The controls are mapped to ISO 27001:2022 Annex A by reference.
Should we do the 5-Day Diagnostic first?
Usually yes, when the workspace already exists and nobody is sure what is in it. The Diagnostic finds the real boundaries and surprises before anything is priced, and the $750 comes off the balance.
Do you need access to sensitive data?
No. Boundaries and permissions are designed on classifications and tested on non-sensitive records. Sensitive data moves in after the access model is proven, and only by your people.
What if we are fewer than 25 people?
Then the question is whether a third party will ask for proof. Two partner organizations sharing one workspace need this at eight people. A single team of 30 with no external parties is usually the 10-Day Build, and I will say so on the call.
Why a deposit and a balance rather than one payment?
Because you should not pay $12,500 for an architecture you have not read. The deposit covers the mapping and the design. The balance is due only once you have approved it.
Start where the problem is. Every step counts toward the next.
The 5-Day Diagnostic. One unresolved problem. A 90-minute call, a documented test in your
workspace, a written recommendation in five working days. Credited in full against either build.
Start the Diagnostic →
The 10-Day Build. One team, one workspace. You know what you need and you want it built, migrated
and handed over working. Working in ten days or free.
See the build →
The 20-Day Governance Build. This page. Several entities or partners, 25+ people, or a third
party who needs proof. Two at a time.
Apply for a slot →
Apply for a slot
Six questions, then a free 20-minute Fit Call. I will have read your answers before we speak, and I will tell you whether the Diagnostic should come first.
Answer six questions →