Change Advisory vs Automated Gates
Replacing a weekly board with evidence a machine produces on every change.
6 to work through
-
beginner Multiple choice
A change advisory board meets weekly and approves about 60 changes in a 40-minute meeting. Attendance is good and the minutes are complete. What assurance does the meeting actually provide?
3 min answer -
advanced
A change advisory board reviews all production changes. Engineering wants automated gates. What is the actual trade?
1 min answer -
advanced
A payments and ride-hailing platform of Grab's shape replaced its weekly change advisory board with automated gates fourteen months ago. At 23:40 a configuration change reaches production through the emergency path and skips the canary stage. By 23:46 card authorisations are failing in two markets; recovery takes 51 minutes. The review finds that 38% of production changes in the previous quarter used the emergency path, median approval 90 seconds by whoever was on call. What failed?
3 min answer -
advanced
An organisation's change advisory board is slow and, by its own incident data, is not preventing failures. What should replace it, and what genuinely requires human review?
2 min answer -
advanced
How would you replace a change advisory board without weakening control?
2 min answer -
advanced
Reddit's 14 March 2023 outage ran 314 minutes after a Kubernetes 1.23 to 1.24 upgrade removed the node-role.kubernetes.io/master label that Calico route reflector selectors depended on, and Kubernetes has no supported downgrade. Sequence the next cluster upgrade so a gate can actually block it.
3 min answer
3 terms in this topic
Break-Glass Change Ratio
The share of production changes that took the emergency path instead of the gated one, which measures how much of the change population a control act…
conceptChange Advisory versus Automated Gates
Whether change is controlled by human review or by automated verification — where the evidence favours automation and the regulation increasingly per…
practiceEvidence Based Approval
Replacing a human judgement about whether a change is safe with a machine-produced record of the checks it passed, assessed once for the class rather…
Neighbouring topics
Assurance, Audit & Model Risk
General material on assurance, architectural governance and risk oversight.
Control Design vs Operation
A control that is well designed and never runs fails exactly like one that is absent.
Audit Evidence
Producing durable, tamper-evident proof as a by-product rather than as a project.
Certification Impact on Architecture
What SOC 2 and ISO 27001 actually require of a design, and what they do not.
Continuous Controls Monitoring
Testing controls continuously instead of sampling them once a year.
Segregation of Duties
Splitting authority so no single actor can both make and approve a change.
Risk Appetite
The stated tolerance that tells you which risks you are allowed to accept.
Risk Assessment Methods
Qualitative matrices, FAIR and scenario analysis, and the illusion of a precise score.
Security Design Review
Reviewing an architecture for security while changing it is still cheap.
Architecture Compliance Checks
Automating conformance to standards so review effort goes to the genuinely novel.
Exception & Waiver Management
Time-boxed, owned deviations with a remediation date, rather than permanent silence.
Design Authority
How an ARB should decide, what it should not review, and how it avoids becoming a queue.
Three Lines Model
Ownership, oversight and independent assurance, and where architecture sits in it.
Model Risk Management
Inventory, validation, monitoring and challenge for models that make consequential decisions.
AI Risk Tiering
Classifying a use case by potential harm, and the obligations each tier triggers.
Model Documentation
Model cards, intended use, limitations, and the record a regulator will ask for.
Model Evaluation & Red-Teaming
Adversarial testing of a probabilistic system with no fixed expected output.
Bias & Fairness Controls
Measuring disparate outcomes, choosing a fairness definition, and living with the trade-off.
Human-in-the-Loop Design
Meaningful review rather than a rubber stamp, and designing against automation bias.