Roadmap
Where DevGob is going, and what is already there
DevGob governs your delivery and connects to the repositories and pipelines you already run — it does not replace them. Every status below describes the product as shipped today.
- Available
- In progress
- Planned
Critical priority
What an organization needs to adopt DevGob alongside its current tools and pass an audit with it.
-
Available
Advanced GitHub integration
Branches, commits, pull requests with reviews, CI runs and releases on each work item, kept current by webhooks.
-
Available
Single sign-on with OIDC
Okta, Microsoft Entra ID, Google or any OpenID Connect provider, per organization.
-
Available
MFA with TOTP
A second factor from any authenticator app.
-
Available
Audit log export
The audit log as CSV, with the filters applied on screen.
-
Available
Audit Evidence Package
One ZIP per change: change request, business case, requirements, pull requests, tests, committees, evidence and audit trail, hashed and signed.
-
In progress
Complete REST API
Work items, deployments, backlog, boards and reports are available; the remaining modules are being added.
-
Planned
Azure DevOps integration
Repos, pull requests and pipelines from Azure DevOps on each work item, as with GitHub.
-
Planned
GitLab integration
Merge requests, commits and pipelines from GitLab.
-
Planned
Outgoing webhooks
Notify other systems when a change advances, is authorized or is installed.
-
Planned
Enterprise backup and restore
Scheduled, verifiable backups of an organization's data, restorable on demand.
-
Planned
Disaster recovery
A documented, tested recovery plan with defined recovery objectives.
Next
Enterprise identity, approvals where people already work, and richer change governance.
-
In progress
Normal, Standard and Emergency changes
Every change is classified today; dedicated paths — pre-approved standard changes, expedited emergency changes — are next.
-
Planned
SCIM provisioning
Users and groups kept in sync from your identity provider.
-
Planned
SAML single sign-on
For identity providers that speak SAML instead of OIDC.
-
Planned
SIEM integration
The audit trail streamed to your security information and event management system.
-
Planned
Approvals from Microsoft Teams and Slack
Committee decisions recorded from the conversation, with the same audit trail.
-
Planned
Electronic approval and signature
Signed approvals for organizations that require them.
-
Planned
Risk scoring
A suggested risk level from the change's history and scope, next to today's manual rating.
-
Planned
Change calendar
Every scheduled installation on one calendar, with freeze windows.
-
Planned
Conflict detection
A warning when two changes touch the same component in the same window.
-
Planned
Post-implementation review
A structured review after installation, kept with the change.
Later: compliance packs
Ready-made mappings between the evidence DevGob produces and the controls of each framework.
-
Planned
ISO/IEC 27001
Change management and operations security controls.
-
Planned
NIST
Configuration and change control families.
-
Planned
SOC 2
Change management criteria.
-
Planned
ITIL Change Enablement
Change types, authorities and reviews.
-
Planned
PCI DSS
Change control requirements for cardholder data environments.
Compliance support, not certification
DevGob produces the evidence an audit asks for and helps map it to the controls of each framework. It does not certify your organization, and holds no certification of its own for these frameworks: a certification is granted by an accredited body after an audit of your organization.
Need one of these first?
Tell us what your organization needs; customer requests decide the order inside each stage.