Software change auditing and audit evidence
Answer any audit about your software changes: who requested, built, tested and approved each one, with a signed evidence package per change.
2 min read
What an auditor asks about a change
- Who requested it and why.
- Which requirement and business case it belongs to.
- Who wrote the code and who reviewed it.
- Which tests were run, where, and with what result.
- Who authorized it and when.
- What evidence proves it was installed as approved.
Why audits take so long
The answers usually exist, but scattered: tickets in one tool, approvals in email, test evidence in shared folders, logs somewhere else. Assembling them for a sample of changes takes weeks — and the gaps appear exactly where nobody kept a record.
One evidence package per change
DevGob generates a ZIP for each deployment or data change with the change request, business case, requirements, pull requests, commits, test results, committee decisions, rollback plan, the evidence files of each phase and the audit trail.
- Manifest.sha256 with the hash of every file.
- Manifest.sig: an Ed25519 signature of the manifest.
- A published public key to verify it independently.
- Every download recorded in the audit log.
An audit log that cannot be edited
State transitions, phase changes, permission changes and denied access are written to an append-only audit log, which can be filtered and exported as CSV.
How DevGob helps
DevGob records the evidence of each change while the work happens and hands it to the auditor as one hashed, signed package.
Read it in the documentationFrequently asked questions
Can an auditor verify a package without DevGob?
Yes, with sha256sum and openssl, comparing the key in the package with the one published at /.well-known/devgob-evidence-key.
Who can download the evidence?
Anyone with the evidence.export permission and access to the change: by default administrators, project managers, release managers, committee approvers, data administrators and auditors.
Is there a role for auditors?
Yes. The Auditor role reviews the work and its evidence without changing it.
Keep reading
DevOps with governance, on one record
DevGob plans the work and governs every change on its way to production: backlog, sprints, committee authorizations, install evidence and an audit trail.