DevOps Professional · Module 6: Governance, cost and change control
Change Plans Against Permission, Approval and Audit Rules
Change control is not bureaucracy, it is premeditation. The plan declares what changes and why, permission checks the actor, approval checks the organization, audit proves it happened, and the L65 lab verifies a plan against all three.
10 min reading
Objectives
- Explain what a change plan declares: what, why, blast radius, way back
- Verify permission (may I), approval (may we) and audit (prove it) before acting
- Reject plans whose blast radius exceeds their evidence
- Record the decision so the history explains itself
Why this matters
A change runs at midnight with no written plan: the blast radius was imagined, the way back was hoped, and the incident review reconstructs intentions from chat fragments. The change might have been correct; without a plan nobody can tell, and the next identical change carries the same risk. Plans convert courage into procedure: the same bold change, written, checked and recorded, is safe to repeat and safe to review.
Concepts
The plan has five lines. What changes (exact scope, commands, manifests). Why (the reason with its evidence). Blast radius (who feels it, how bad, how detected). Way back (the tested reversal path with its own verification). Verification (how we know it worked, user-shaped). A plan missing any line is a draft; drafts do not run in production, whatever the schedule pressure.
Three gates check the plan. Permission: the actor's identity holds the narrow role for exactly this action (M17's least privilege applied to humans). Approval: the change's risk tier names its approvers, and they approve the written plan, not a hallway summary. Audit: the action logs who, what, which approval, with before-and-after evidence attached automatically. Skipping any gate converts the plan from control into theater.
Blast radius gates evidence. Small radius with verification needs a light plan and peer approval; large radius needs staged rollout, canary evidence and senior approval with the incident commander aware. The radius sets the ceremony, and inflating ceremony for small changes teaches evasion while starving big changes of scrutiny. Calibrate on schedule from incident history: which tier produced surprises, which produced only paperwork.
Worked example
A fixture change plan arrives with an overstated-small radius. The learner checks permission (held), approval (wrong tier for the real radius), and audit readiness (missing evidence hooks), then rejects with the specific gaps quoted. The revised plan returns with staged rollout, correct approvers and evidence hooks, and passes all three gates with the decision recorded.
Common wrong move
Approving the person instead of the plan. Trusted engineers make mistakes at the same rate; the plan is what catches them, and waiving it for seniors teaches juniors that process is punishment. Same gates, everyone, every time.
Quick check
An optional 4-question self-check. Answers never leave your device, are not stored, and never count toward any assessment.
Lesson feedback
No published feedback yet.
Log in and complete the lesson to leave feedback.
Exercise
Verify a fixture change plan against permission, approval and audit rules, reject it with quoted gaps, and pass the revised plan with the decision recorded.
Pass criteria
The record shows the three gate checks, the quoted rejection gaps, and the revised plan passing with its recorded decision.