Platform module
Change management that produces its own evidence
Auditors sample changes and ask for the request, the approval, the review and the deployment record. Certifyi collects those from your code hosting and ticketing tools as changes happen, so the sample is already there.
What change management means for an audit. SOC 2 (CC8.1), ISO 27001 (A.8.32) and CMMC (3.4.3) require that changes to systems are requested, approved, tested and recorded, and that emergency changes are reviewed afterwards. The evidence is a set of changes with those four records attached.
What it does
Approve
Change requests with approvals
Requests, approvers and approval timestamps recorded, with separation between the person who requests and the person who approves.
Review
Code review evidence
Pull requests, reviewers and merge records from GitHub or GitLab attached to the change automatically.
Deploy
Deployment records
Deployment approvals, environments and times from CI and ticketing systems, linked to the change and the assets affected.
Exceptions
Emergency change review
Emergency changes flagged, reviewed after the fact and evidenced, which is the exception auditors look for first.
Baseline
Configuration baselines
Changes compared against approved baselines so drift shows as a change that never had a request.
Audit
Sampling ready
Auditors pick any period and see the population of changes with the four records, hashed and timestamped.
How it works
The same record your auditor, your vendors and your team already use.
Step 1
Request
A ticket or pull request opens the change with scope and risk.
Step 2
Approve
Named approver, recorded separately from the requester.
Step 3
Review and test
Code review and test evidence collected from the tools.
Step 4
Deploy and record
Deployment record closes the change; drift checks confirm it.
Questions about this module
Do we need a change advisory board?
No. Frameworks require a documented process with approvals and records, not a committee. A reviewer other than the author, recorded in the tool, satisfies most requirements for engineering changes.
What counts as an emergency change?
A change deployed before the normal approval to restore service or fix a security issue. It must be reviewed and approved after the fact, and that review is the evidence.
Which tools does this pull from?
GitHub, GitLab, Jira, Linear, Asana and CI systems through the integrations page.
See it on your own scope
Twenty minutes with a compliance lead. Bring your stack; we will show the module against your controls.