Governance runs before the data lands, not afterprocessesAction required
Ownership, sovereignty and policy checks now run as a pre-hook, so a record that fails a check never enters the governed store.
Every decision is recorded against the process instance that triggered it, so a refused write is traceable to the rule that refused it.