Software change auditing and audit evidence

Answer any audit about your software changes: who requested, built, tested and approved each one, with a signed evidence package per change.

2 min read

What an auditor asks about a change

  • Who requested it and why.
  • Which requirement and business case it belongs to.
  • Who wrote the code and who reviewed it.
  • Which tests were run, where, and with what result.
  • Who authorized it and when.
  • What evidence proves it was installed as approved.

Why audits take so long

The answers usually exist, but scattered: tickets in one tool, approvals in email, test evidence in shared folders, logs somewhere else. Assembling them for a sample of changes takes weeks — and the gaps appear exactly where nobody kept a record.

One evidence package per change

DevGob generates a ZIP for each deployment or data change with the change request, business case, requirements, pull requests, commits, test results, committee decisions, rollback plan, the evidence files of each phase and the audit trail.

  • Manifest.sha256 with the hash of every file.
  • Manifest.sig: an Ed25519 signature of the manifest.
  • A published public key to verify it independently.
  • Every download recorded in the audit log.

An audit log that cannot be edited

State transitions, phase changes, permission changes and denied access are written to an append-only audit log, which can be filtered and exported as CSV.

How DevGob helps

DevGob records the evidence of each change while the work happens and hands it to the auditor as one hashed, signed package.

Read it in the documentation

Frequently asked questions

Can an auditor verify a package without DevGob?

Yes, with sha256sum and openssl, comparing the key in the package with the one published at /.well-known/devgob-evidence-key.

Who can download the evidence?

Anyone with the evidence.export permission and access to the change: by default administrators, project managers, release managers, committee approvers, data administrators and auditors.

Is there a role for auditors?

Yes. The Auditor role reviews the work and its evidence without changing it.

DevOps with governance, on one record

DevGob plans the work and governs every change on its way to production: backlog, sprints, committee authorizations, install evidence and an audit trail.