← Back to Knowledge CentreInsight

The Communication Identifier Governance Maturity Model

Five stages from Fragmented to Extending. Where is your estate today — and what does the next stage actually require? A self-assessment framework for the identifier estate.

Once an organisation accepts that its communication identifier estate needs governing, the useful question stops being whether there's a problem and becomes where are we, and what does the next step actually require? Maturity language answers that. Every estate is at some stage of this model today — including estates whose owners have never thought about them at all. That, in fact, is stage one.

The five stages

Stage 1 — Fragmented. No authoritative record exists. Knowledge of the estate lives in carrier portals, admin consoles and spreadsheets that disagree with each other, and the truth lives in a few people's heads. The tell-tale symptom: asked how many identifiers the organisation holds, different teams give different answers — and none would bet on their own. Movement out of stage 1 usually starts with a shock: an audit, an acquisition, a migration that stalls on discovery.

Stage 2 — Inventoried. A consolidation effort has produced a master record — and it was accurate the day it was finished. Nothing forces changes through it, so it decays: numbers port, services migrate, new sender IDs appear, and the record quietly diverges from reality. Stage 2 organisations can answer "how many?" — as of the last project. The symptom: the master spreadsheet has a version number, and everyone knows which columns not to trust.

Stage 3 — Managed. Real lifecycle tooling operates — but per domain. Numbers are managed in one system, SIP identities in another, messaging registrations in a third, each with its own owner and process. Governance exists as stage-gates and periodic audits, not as a layer: changes are reviewed somewhere, evidence is assembled afterwards. Stage 3 is where most organisations with serious telecom operations sit, and it feels like competence — right up until a question crosses domains.

Stage 4 — Governed. The relationship between record and change inverts: changes go through the governed record, ownership and policy are checked before execution rather than reviewed after, and evidence accumulates as a by-product of operating instead of being reconstructed under pressure. One layer spans every domain, so cross-cutting questions — who owns this, what depends on it, who authorised that — have one answer. This is the stage where the category's outcomes actually land: cost recovery, operational efficiency, audit readiness.

Stage 5 — Extending. The governed discipline extends as the estate grows. New identifier domains, new markets and machine-issued identities enter the estate already governed — there is no backlog of ungoverned acquisitions waiting for the next cleanup, because nothing enters outside the layer. Stage 5 is not a product feature; it is what governance looks like once it is genuinely an operating posture rather than a project that ended.

Three questions locate you

The fastest self-assessment is the same three questions a board should ask. Can we count the estate? — one number, from one governed record (stages 1–2 fail here). Can we prove control of it? — for any identifier, its owner, its policy, and evidence of who authorised its last change, on demand (stage 3 fails here; it can prove things, but only by reconstruction). Who owns its governance? — a named owner of the operating layer, not a shared assumption between IT, security, compliance and finance (the question that separates stage 4 from everything below it).

Maturity is not uniform — and that's the point

Almost no organisation occupies one stage across its whole estate. A telecoms-heavy enterprise is often stage 3 or 4 on telephone numbers, stage 2 on SIP identities, and stage 1 on messaging sender IDs and AI-issued identities — because each domain was acquired by a different team, on a different timeline, with different tooling. Assessing per dimension — visibility, ownership, policy and authorisation, evidence, lifecycle automation, and domain coverage — turns a vague sense of "we should be better at this" into a specific map: which domains, which dimensions, which stage. The gap between your best-governed domain and your worst is usually where the unpriced risk sits.

Using the model

Two ways in. Self-assess: take the three questions, apply them per identifier domain, and be honest about which answers are "yes," which are "yes, given a week to prepare," and which are "it depends who you ask." Or do it with us: the assessment is a structured working session with your real estate that locates you on this model, dimension by dimension — and you keep the findings either way.

What to read next

If the stages describe symptoms you recognise but you want the underlying argument, start with what Communication Identifier Governance actually means. If you're at stages 1–2, seeing the whole identifier estate at once is about exactly your problem — including why the stage-2 consolidation project keeps failing. If you're at stage 3 and evaluating what stage 4 takes, the architecture overview shows the platform that implements the governed layer — and how to evaluate a Communication Identifier Governance platform gives you the criteria and vendor questions to run that evaluation with, against us included.

Wondering where your own estate stands? Arrange an assessment