PayPal exec maps a path to adopting shift-left data governance
Moving data governance upstream can help build trusted data for users and AI. PayPal governance leader Brandy O'Shields explains how to adopt a shift-left approach.
For Brandy O'Shields, senior manager of enterprise data governance at PayPal, the traditional governance model of identifying and resolving data issues after systems are deployed isn't good enough anymore. Instead, she said, organizations need a shift-left approach that builds governance into data architecture and application design from the start.
Moving governance upstream in the data lifecycle is critical in the AI era, according to O'Shields and other speakers at Dataversity's Data Architecture Online 2026 conference. Embedding data governance processes in the design and development stages helps organizations create trusted, AI-ready datasets that are properly classified for security and privacy protections, O'Shields said during a presentation.
But shift-left data governance also has broader business benefits, she added. Data quality issues can be caught before applications are deployed, rather than being discovered by users -- or, worse, overlooked entirely. Upfront documentation of data ownership and lineage enables teams to resolve issues faster. Earlier data classification drives stronger access controls. Compliance with regulations and internal policies requires less rework.
"Shift-left is an opportunity for us to look at a more efficient way to insert governance into the [data management] process," O'Shields said. Ultimately, she noted, adopting shift-left methods should make it easier to ensure high-quality, trusted data flows through an organization's data pipelines to end users and AI systems alike.
What shift-left governance includes
Shift-left is the operational component of governance by design, an overarching strategy for incorporating governance processes into data architectures. As part of shift-left governance, data classification, lineage, retention and residency requirements are built into platform and application design specifications from Day 1, O'Shields said. She added that governance leaders should also include schema definitions, data descriptions and validated data ownership documentation in a "hard gate" of requirements that must be met before systems and applications go into production.
To facilitate that, O'Shields said data governance teams should participate in design reviews and work with software engineering units to define data contracts, particularly to specify metadata attributes that must be captured in systems when data is created. She recommended including mandatory attributes in the following categories as part of a data contract, along with validation rules for each attribute:
From a data flow perspective, you have an opportunity to embed governance all along the way.
Brandy O'ShieldsSenior manager of enterprise data governance, PayPal
Business, technical and operational metadata.
Data provenance.
Data classification.
Regulatory compliance.
Data lifecycle management.
Security protections.
But O'Shields cautioned against being "too heavy-handed" in the contract, saying that could steal energy from governance efforts. Governance teams should also automate the population of metadata attributes in data pipelines as much as possible to simplify the process for software developers, she said.
Similarly, she advised that metadata validation rules be built into CI/CD pipelines and schema registries for automated enforcement. "From a data flow perspective, you have an opportunity to embed governance all along the way," O'Shields said.
AI's potential role in shift-left data governance
AI tools and agents can help by automating governance tasks such as classification, metadata generation and data quality monitoring in shift-left environments, O'Shields said. That reduces manual work for governance teams, freeing them to focus on more complex functions.
AI can also assist with policy-as-code implementations, which convert governance policies into machine-readable code to automate enforcement in data pipelines in a consistent, auditable way. For example, O'Shields said teams could use large language models to generate YAML scripts from governance policy documents.
But the use of AI in data governance does require human oversight -- or "humans above the loop," as O'Shields put it. She said the necessary oversight can be provided by both governance professionals and data owners, who are often best positioned to verify the accuracy of AI outputs related to their datasets.
Another lesson learned from shift-left initiatives at PayPal is the need to foster close relationships between governance, data architecture and software engineering teams to build mutual trust. O'Shields said leaders should also create shared objectives and key results, or OKRs, for the teams. Their performance can then be evaluated against the same ROI outcomes, such as increased data quality and faster application delivery -- the latter achieved by catching governance issues early and avoiding time-consuming remediation work later.
In addition, O'Shields said governance leaders can grease the skids for the adoption of shift-left principles by initially attaching them to a planned IT infrastructure initiative, such as a cloud migration project. That provides a concrete vehicle for launching a shift-left governance program, with senior executives and data architecture teams already looking to deploy new systems and processes.
Shift-left approaches aid AI readiness
In a separate panel discussion on creating AI-ready data architectures, Aashoo Saxena, vice president of product management at Salesforce's Informatica unit, said treating data governance as a post-deployment afterthought isn't an effective way to build one. To achieve optimal AI results, he said organizations need to think about governance from the ground up.
In particular, agentic AI changes the governance equation, Saxena added. Integrating data quality, lineage, traceability and compliance mechanisms into data pipelines is a must to ensure the data used by autonomous AI agents is trustworthy and understandable, he said. If it isn't, an organization won't be able to trust the AI outputs.
Kevin Fair, sales leader for information architecture data integration at IBM, said many AI projects fail to deliver the expected ROI because organizations rush to deploy them without solid data governance in place. "If we're simply looking to dump [the data] in and then try to figure out what we have after the fact, that's where these projects get costly and really start to struggle," Fair said.
Adopting a shift-left approach that applies governance and quality rules as data is ingested and moves through pipelines better sets up AI applications for success, he added. When an AI model is trained on clean, consistent and well-documented data, Fair said, "we can feel confident that we've taught it well."
Craig Stedman is an industry editor at TechTarget who focuses on data technologies and processes. He has covered enterprise IT as a reporter and editor for more than 40 years.