{"description":"Runs on the existing system item. Move a system change from request through independent testing and approval to production migration, evidencing developer-migrator segregation. Deliver the reviewed result and open actions to the responsible register owner and the named companion procedure.","edges":[{"id":"e-change-approval-change-closure","source":"change-approval","target":"change-closure"}],"isPublic":true,"itemTypeSlug":"system","metadata":{"capabilities":["change-request-approval-migration"],"controlVerbs":{"UC-SDLC-07":"operates"},"controls":["UC-SDLC-07"],"department":"it","domains":["controls"],"kind":"change-request-approval-migration","library":{"aliases":[{"source":"studio-seed","sourceTemplateId":"coworkcanvas:template:change-request-approval-migration"}],"canonicalUrl":"https://workflow-library.com/all/?w=controls-system-change-approval-migration","contentDigest":"sha256:b7a02e83141c52306773f1ca95808c5b085b6bed12cb7151e0542d7b204bf9b2","prerequisites":{"anchorItemType":{"slug":"system"},"evidenceDestinations":[{"description":"Restricted native step results, attached documents, durable item fields and native approvals.","id":"review-evidence"}],"handoffs":[{"direction":"output","name":"Reviewed register result and open actions","sourceTemplateId":"workflow-library:controls-change-release-management-operation"}],"roles":[{"contribution":"approval","description":"Independent change approver. Obtain approval and test evidence.","id":"reviewer-1","nodeIds":["change-approval"]},{"contribution":"approval","description":"Independent release reviewer. Approve change record.","id":"reviewer-2","nodeIds":["change-closure"]}],"status":"declared"},"provenance":[{"source":"brain/scripts/studio-seed","sourceTemplateId":"coworkcanvas:template:change-request-approval-migration"}],"releaseId":"sha256:b7a02e83141c52306773f1ca95808c5b085b6bed12cb7151e0542d7b204bf9b2","schemaVersion":1,"sourceTemplateId":"workflow-library:controls-system-change-approval-migration"},"lineOfDefense":"operate","mappingStatus":"mapped","risks":[],"slug":"controls-system-change-approval-migration","source":"coworkcanvas-gallery","standards":[],"teams":["it"]},"name":"Change Request, Approval & Migration","nodes":[{"data":{"instructions":"**Objective**\nObtain approval and test evidence. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Review the System item, the change record, requirements or defect reference, affected component and interface inventory, the change classification policy, and the release calendar.\n2. Use the change record, test plans and executed results, defect logs and retest evidence, user acceptance sign-off, the approver identity and role, and the developer identity.\n\n**Procedure**\n1. Verify the change is recorded before work began, confirm the classification drives the correct approval path, identify affected downstream interfaces and reporting, and flag changes classified below their actual risk.\n2. Inspect executed test results rather than a test plan, confirm the approver is independent of the developer by identity comparison, verify conditions of approval are recorded, and refuse approval evidenced only by workflow status.\n\n**Record in AssureSwarm**\n1. Capture the change reference, requester and business reason, affected components and interfaces, classification with rationale, required approval path, target release window, and classification challenges raised. Also record change description and classification.\n2. Document test evidence with dates and executor, defects raised and retested, approver identity and independence basis, approval status and conditions, and testing the change did not receive.\n\n**Exit criteria**\nIndependent change approver provides approval: The change is recorded in advance with an evidenced classification, the approval path follows from the classification, and under-classification is challenged rather than accepted. Testing is evidenced by executed results, approver independence is demonstrated by identity rather than assumed, and approval conditions are recorded before migration.","kind":"task","label":"Obtain approval and test evidence","requiredApprovals":1},"id":"change-approval"},{"data":{"controls":["UC-SDLC-07"],"instructions":"**Objective**\nApprove change record. The reviewer decides from the complete package described below.\n\n**Inputs**\n1. Use the approved change package, deployment pipeline and migration logs, production verification results, the migrator identity, rollback plan, and post-migration monitoring.\n2. Review all stage records, classification rationale, executed test evidence, approver and migrator identities, deployed-versus-approved comparison, and open post-migration issues.\n\n**Procedure**\n1. Compare the deployed artifact against the approved package rather than trusting the pipeline, confirm migrator identity differs from developer identity, verify post-migration behaviour, and record an unsegregated migration as a control exception.\n2. Trace the deployed change to an approval and executed tests, verify both independence checks rest on identity evidence, confirm open issues carry owners, and return approvals evidenced only by status with precise comments.\n\n**Record in AssureSwarm**\n1. Record the migration outcome, deployed artifact compared to approval, migrator identity and segregation basis, verification results, issues and rollback actions, and compensating controls where segregation failed. Also record developer/migrator segregation.\n2. Capture the authorized reviewer, the change summary, accepted outcome, migration date, segregation conclusion, compensating controls, open issues with owners and dates, and linked exceptions raised.\n\n**Exit criteria**\nIndependent release reviewer provides approval: An approver accepts that production matches the approved package, segregation is evidenced by identity comparison, and a segregation failure is recorded as an exception rather than waived. The authorized reviewer accepts the record as evidence the change control operated for this change, and closure implies no assurance over changes migrated outside this process.","kind":"task","label":"Approve change record","requiredApprovals":1},"id":"change-closure"}],"sourceTemplateId":"workflow-library:controls-system-change-approval-migration"}
