Three people around one printed document in a daylit meeting room, one of them signing it while the others watch

Product · Governance and audit

Everything that reaches production crosses one line, and signs for it.

Change Control puts your governance inside the promotion path for a production IBM Maximo estate. A change is raised against a named scope, routed by your policy, reviewed with its test results, approved by role, and promoted only where that approval exists.

The boundary

What crosses into production, in which direction, and who signs

Governance written in a policy document and governance held in the promotion path are separate things. Only the second can hold a gate.

What moves From Direction To Signed by
Configuration and screen changes Test environment Production Named change authority
Automation scripts and integration mappings Test environment Production Change authority, with the integration owner named
The approved window Change authority The promotion path Change authority
Promotion outcome and timestamp Production The change record Written by the gate
Anything promoted outside the gate, as an exception Production The change record Written by the gate

What never crosses

  • A change with no approval naming this scope and this window. An approval for a similar change last month is a different record.
  • A change approved by the person who implemented it. Approver, reviewer and implementer are role separated on every record.
  • Anything that was not attached when the reviewer read it. The change is locked to its artefacts.
  • The judgement about whether the change is a good idea. That stays with your people, and the gate records who made it.

One crossing, as a record

CHG-4182, from request to production outcome

One completion code rule, one automation script, three environments. Each line was written at the moment it was decided, by the person deciding it.

Evidence pack for change CHG-4182
Reference CHG-4182
Change Work order status transition refuses to close without a completion code
Scope One tenant, three environments, production last
Artefacts Automation script SCR-118, one security group change, test result TR-9042
Raised Monday 09:12, by the Maximo analyst who built it
Reviewed Monday 14:40, Maximo service owner. Returned once, rollback step not written out
Resubmitted Wednesday 11:05, rollback step and retest evidence attached
Approved Wednesday 16:20, named change authority, for the Thursday 20:00 window
Promoted Thursday 20:14, by the pipeline. Nobody signed in to production
Closed Thursday 20:31, production outcome recorded against this reference

An illustrative record. The reference and the times are examples; the fields are the ones the gate requires before it opens.

The five gates

What passes each gate, and what is held back

Your policy decides how much of this path a low-risk category walks. It does not decide whether the record is written.

  1. Gate 1 Raise against a named scope

    Signed by The person raising it

    Passes

    A change naming its tenant, environments and artefacts, with those artefacts attached at the point of raising.

    Held back

    A change described in prose, with the artefacts to follow.

  2. Gate 2 Classify by your policy

    Signed by Your change policy, as configured

    Passes

    Routine categories take the fast lane your policy defines.

    Held back

    A sensitive category routed as routine because the window is tight.

  3. Gate 3 Review with test evidence

    Signed by Maximo service owner

    Passes

    A reviewer holding the artefacts and the lower-environment results, whose comments stay on the record including a return.

    Held back

    A review held on a screen share, with nothing attached to the record.

  4. Gate 4 Approve by role

    Signed by Named change authority

    Passes

    Approval by a named role, for this change, this scope and this window.

    Held back

    Approval by the analyst who built the change.

  5. Gate 5 Promote

    Signed by Written by the gate

    Passes

    The promotion the approval names, on the environments it names, inside the window it names.

    Held back

    A promotion whose approval covers a different scope, or a window that has closed.

What an auditor receives

An auditor asking for twelve production changes from last quarter receives twelve packs, not a reconstruction.

Evidence assembled months later from tickets, mail threads and screenshots is usually true and always a reconstruction, and it is thinnest where the risk was highest. A record written at approval costs the approver nothing and costs your senior engineers days per audit cycle.

Demonstrated, not described

Five things we demonstrate before you govern a live estate with this

Run in a test tenant on your own change policy, with your people watching.

  1. T1

    Produce the full pack for one change from your last quarter

    Passes when
    Request, artefacts, review comments, approving role, window and outcome sit on one record, with nothing assembled by hand.
    Witnessed by
    Your internal auditor and Maximo service owner
  2. T2

    Refuse a promotion whose approval names a different window

    Passes when
    The gate holds, and the attempt is recorded as a refusal against the change.
    Witnessed by
    Your change authority
  3. T3

    Refuse an approval from the person who implemented the change

    Passes when
    Role separation blocks the approval and names the conflict on the record.
    Witnessed by
    Your change authority
  4. T4

    Show a promotion made around the gate

    Passes when
    It appears as an exception in the change record rather than among the governed changes.
    Witnessed by
    Your Maximo service owner
  5. T5

    Route a sensitive category and a routine category from the same policy

    Passes when
    The routine change clears the fast lane; the sensitive one walks the full path.
    Witnessed by
    Your change manager

Scope and boundaries

Three boundaries on Change Control

Settle each of these during procurement, not at the first audit.

It does not decide whether a change is a good idea

Whether a script should exist, whether the timing suits the operation, whether residual risk is acceptable: those stay with your people. Change Control makes sure the right role decided, and that the decision is on the record.

It cannot create evidence for changes made around it

A change promoted by hand outside the gate has no pack, and none is produced after the event. It is recorded as an exception instead of blending in with the governed changes.

It complements your ITSM rather than competing with it

The production gate on every regulated Maximo estate MaxIron operates, including utilities, oil and gas, transport and public sector. Your service management tool stays the enterprise change record; Change Control holds the gate for Pipelines and higher-impact Autoheal playbooks, and supplies the Maximo-specific evidence underneath the ticket.

MaxIron Change Control, frequently asked questions

What is in the evidence pack for a single change?
The request and the scope it named, the artefacts attached to it, the review comments including any that sent it back, the approving role and the person holding it, the approved window, and what reached production. Every line is written at the point the fact is known first hand.
How does this sit with our ITSM?
Your service management tool stays the enterprise change record. Change Control integrates with it and supplies the Maximo-specific evidence that sits underneath the ticket.
What happens to a change promoted outside the gate?
It has no pack, and none is manufactured after the event. It is recorded as an exception, so exposure appears in your own record rather than in an audit finding.
Does it slow a routine change down?
Routing is set by your policy. Routine categories take a fast lane; the categories your policy treats as sensitive walk the full path.
Can it act as the gate for Pipelines and Autoheal?
Pipelines uses Change Control as its production gate, and higher-impact Autoheal playbooks request approval through it before they run.
Why a Maximo-specific change product?
The approver reads the change in Maximo terms: which tenant, which environments, which script, which integration mapping, against which test result. Change Control complements IBM Maximo and MAS by holding that gate in the promotion path.

Bring your last audit's evidence request.

We walk one of your own changes across the boundary and build the record that would have existed on the day it went into production.

Bring this to the first call

  • Your change policy, and the categories it treats as sensitive
  • The evidence request list from your most recent audit
  • One production change from last quarter you would rather not have to explain
  • The roles designated to approve, and the list of people who currently can