Audit evidence package: every change, provable
DevGob now generates one signed ZIP per change with its requirements, code, tests, approvals, evidence and audit trail. What it contains and why.
1 min read
The problem
Audits of software changes usually start with a sample: twenty changes from last quarter. For each one the auditor wants the request, the review, the tests, the approval and proof of installation — and teams spend days collecting them from five different tools.
What the package contains
- ChangeRequest, BusinessCase and Requirements PDFs.
- PullRequests and Commits, with their CI runs.
- TestResults for each environment.
- The Committee-PRE and Committee-PROD decisions, or the Authorizations of a data change.
- The rollback plan and the evidence folders of each phase.
- AuditTrail.csv, with the item history and the audit log.
Hashed and signed
Every file is listed in Manifest.sha256 with its SHA-256 hash, and the manifest is signed with an Ed25519 key whose public half is published. Anyone can verify the package with sha256sum and openssl, without a DevGob account. Each download is also recorded in the audit log with the manifest's hash.
Who can download it
The new evidence.export permission is granted by default to administrators, project managers, release managers, committee approvers, data administrators and auditors.
Keep reading
DevOps with governance, on one record
DevGob plans the work and governs every change on its way to production: backlog, sprints, committee authorizations, install evidence and an audit trail.