Roadmap

Where DevGob is going, and what is already there

DevGob governs your delivery and connects to the repositories and pipelines you already run — it does not replace them. Every status below describes the product as shipped today.

  • Available
  • In progress
  • Planned

Critical priority

What an organization needs to adopt DevGob alongside its current tools and pass an audit with it.

  • Available

    Advanced GitHub integration

    Branches, commits, pull requests with reviews, CI runs and releases on each work item, kept current by webhooks.

  • Available

    Single sign-on with OIDC

    Okta, Microsoft Entra ID, Google or any OpenID Connect provider, per organization.

  • Available

    MFA with TOTP

    A second factor from any authenticator app.

  • Available

    Audit log export

    The audit log as CSV, with the filters applied on screen.

  • Available

    Audit Evidence Package

    One ZIP per change: change request, business case, requirements, pull requests, tests, committees, evidence and audit trail, hashed and signed.

  • In progress

    Complete REST API

    Work items, deployments, backlog, boards and reports are available; the remaining modules are being added.

  • Planned

    Azure DevOps integration

    Repos, pull requests and pipelines from Azure DevOps on each work item, as with GitHub.

  • Planned

    GitLab integration

    Merge requests, commits and pipelines from GitLab.

  • Planned

    Outgoing webhooks

    Notify other systems when a change advances, is authorized or is installed.

  • Planned

    Enterprise backup and restore

    Scheduled, verifiable backups of an organization's data, restorable on demand.

  • Planned

    Disaster recovery

    A documented, tested recovery plan with defined recovery objectives.

Next

Enterprise identity, approvals where people already work, and richer change governance.

  • In progress

    Normal, Standard and Emergency changes

    Every change is classified today; dedicated paths — pre-approved standard changes, expedited emergency changes — are next.

  • Planned

    SCIM provisioning

    Users and groups kept in sync from your identity provider.

  • Planned

    SAML single sign-on

    For identity providers that speak SAML instead of OIDC.

  • Planned

    SIEM integration

    The audit trail streamed to your security information and event management system.

  • Planned

    Approvals from Microsoft Teams and Slack

    Committee decisions recorded from the conversation, with the same audit trail.

  • Planned

    Electronic approval and signature

    Signed approvals for organizations that require them.

  • Planned

    Risk scoring

    A suggested risk level from the change's history and scope, next to today's manual rating.

  • Planned

    Change calendar

    Every scheduled installation on one calendar, with freeze windows.

  • Planned

    Conflict detection

    A warning when two changes touch the same component in the same window.

  • Planned

    Post-implementation review

    A structured review after installation, kept with the change.

Later: compliance packs

Ready-made mappings between the evidence DevGob produces and the controls of each framework.

  • Planned

    ISO/IEC 27001

    Change management and operations security controls.

  • Planned

    NIST

    Configuration and change control families.

  • Planned

    SOC 2

    Change management criteria.

  • Planned

    ITIL Change Enablement

    Change types, authorities and reviews.

  • Planned

    PCI DSS

    Change control requirements for cardholder data environments.

Compliance support, not certification

DevGob produces the evidence an audit asks for and helps map it to the controls of each framework. It does not certify your organization, and holds no certification of its own for these frameworks: a certification is granted by an accredited body after an audit of your organization.

Need one of these first?

Tell us what your organization needs; customer requests decide the order inside each stage.