Platform module

Change management that produces its own evidence

Auditors sample changes and ask for the request, the approval, the review and the deployment record. Certifyi collects those from your code hosting and ticketing tools as changes happen, so the sample is already there.
What change management means for an audit. SOC 2 (CC8.1), ISO 27001 (A.8.32) and CMMC (3.4.3) require that changes to systems are requested, approved, tested and recorded, and that emergency changes are reviewed afterwards. The evidence is a set of changes with those four records attached.

What it does

Approve

Change requests with approvals

Requests, approvers and approval timestamps recorded, with separation between the person who requests and the person who approves.

Review

Code review evidence

Pull requests, reviewers and merge records from GitHub or GitLab attached to the change automatically.

Deploy

Deployment records

Deployment approvals, environments and times from CI and ticketing systems, linked to the change and the assets affected.

Exceptions

Emergency change review

Emergency changes flagged, reviewed after the fact and evidenced, which is the exception auditors look for first.

Baseline

Configuration baselines

Changes compared against approved baselines so drift shows as a change that never had a request.

Audit

Sampling ready

Auditors pick any period and see the population of changes with the four records, hashed and timestamped.

How it works

The same record your auditor, your vendors and your team already use.

Step 1

Request

A ticket or pull request opens the change with scope and risk.

Step 2

Approve

Named approver, recorded separately from the requester.

Step 3

Review and test

Code review and test evidence collected from the tools.

Step 4

Deploy and record

Deployment record closes the change; drift checks confirm it.

Questions about this module

No. Frameworks require a documented process with approvals and records, not a committee. A reviewer other than the author, recorded in the tool, satisfies most requirements for engineering changes.

A change deployed before the normal approval to restore service or fix a security issue. It must be reviewed and approved after the fact, and that review is the evidence.

GitHub, GitLab, Jira, Linear, Asana and CI systems through the integrations page.

See it on your own scope

Twenty minutes with a compliance lead. Bring your stack; we will show the module against your controls.
Scroll to Top