Need help with your APIs? I offer API discovery, governance & evangelism services. Explore services →
API Evangelist API Evangelist
Discovery
Learnings
Guidance
Toolbox
Alignment
API Evangelist LLC
Production

Production

Governing APIs that are live and serving real traffic

Production is where APIs stop being artifacts and become operational reality — live, serving real traffic, with real consumers depending on them — and governing the producing side is one of the two great halves of API governance. For years, the conversation about producing APIs focused on the technical act of building and deploying them, but I’ve come to see API production as fundamentally a governance discipline: the question isn’t just how you build an API but how you govern the process of producing APIs at scale, consistently, with quality, across an organization. Production governance is about ensuring that the APIs your organization puts into the world meet a standard — that they’re consistent, secure, documented, reliable, and aligned with the organization’s practices — rather than being a chaotic sprawl of inconsistent, ungoverned services. The producing side is where governance has the most leverage, because it’s where you can shape APIs before they’re loose in the world.

The provider responsibilities are the foundation of production governance, and I’ve been articulating them for a long time. I wrote in 2014 about reworking my API 101 content to cover providing APIs, and the 10 API commandments for providers — establishing that being an API producer carries real obligations: clear documentation, consistent design, reliable operation, honest communication, responsible deprecation. Production governance is the systematization of these provider responsibilities into a discipline that applies consistently across an organization. The minimum bar for business API operations that I sketched in 2017 was an attempt to define what production-grade actually means — the baseline of practices an API has to meet to be considered properly produced rather than just thrown over the wall. Production governance turns these provider responsibilities from individual virtue into organizational standard.

The path to production is the governance journey an API takes from design to live operation, and the VA example crystallized it for me. I wrote in 2018 about the path to production for VA API applications — the defined, governed process through which an API moves from being designed to being live and serving real consumers. This path is where production governance happens: the design review, the security check, the documentation requirement, the testing gate, the approval to go live. A well-governed production process means that every API that reaches production has passed through the same gates, met the same standards, and earned its place in the live environment. An ungoverned production process means APIs reach production however they happen to, with wildly varying quality and no consistency. The path to production is the operational expression of production governance — the sequence of gates and standards that an API has to pass to become live.

The shift from design-time to operational governance is the maturation that makes production governance complete. I wrote in 2020 about API lifecycle governance beyond just API design, and in 2022 about moving beyond design governance toward operational governance — because for years governance focused on the early, design-time stages while neglecting the operational reality of APIs in production. Governing production means governing not just how an API is designed but how it’s deployed, secured, monitored, and operated once it’s live. The producing side of governance has to extend all the way through to production operations, because an API that was beautifully designed but is poorly operated in production is still a failure. Production governance is the recognition that governance has to follow the API into the live environment, ensuring it meets standards not just at design time but throughout its operational life.

The producing-versus-consuming distinction frames why production governance is one half of a whole. I’ve written extensively about both the producing side and the consuming side of APIs, and production governance is the producing-side discipline — governing how your organization produces and operates the APIs it puts into the world. This is distinct from consumption governance, which governs how your organization consumes the APIs it depends on. Both are necessary, and a complete governance practice covers both. But the producing side is where you have the most control and the most responsibility, because these are your APIs, your standards, your reputation. When I write about establishing a common API lifecycle, I’m describing the framework that production governance operates within — the shared, governed process through which all of an organization’s APIs are produced, so that production becomes consistent rather than chaotic.

The deeper governance question, which I sharpened in 2025, is knowing what you’re actually governing when you say “API governance” in the production context. I wrote about what it is you’re governing when you say API governance — and in production, the answer is: you’re governing the consistency, quality, security, and reliability of the live APIs your organization produces and operates. Production governance is what stands between an organization and the API sprawl that results when every team produces APIs however they like with no shared standard. It’s the discipline that ensures the APIs reaching production are consistent enough to be governable, documented enough to be usable, secure enough to be safe, and reliable enough to be depended on. The baseline rules for governance — including the emerging discipline of consumption governance that complements it — all ultimately exist to ensure that the APIs an organization produces and the APIs it consumes meet a standard worthy of the real traffic and real dependencies they carry. Production is where governance becomes operationally real, where the standards either hold or don’t, where the APIs your organization puts into the world either reflect a governed discipline or betray its absence. Governing production well means ensuring that everything reaching the live environment has earned its place there by meeting the organization’s standards — which is, in the end, what governance is for.

References