Domain status

Active

Workflow dispatch guard is canonical; deployment guard available under engagement.

Workflow guard

Deployment & Config Change Guard

Shipped

Part of Infrastructure & DevOps

Guard readout

Status
Shipped
Control steps
05
// RISK BEFORE HUMBLEAF

Production configuration or secrets change via automation; teams discover it from logs after the fact.

// CONTROLLED FLOW
  • 01Config or secret change proposed
  • 02Policy evaluates production-touching rules
  • 03Risk advises on baseline deviation
  • 04Production-touching changes escalate to approval
  • 05Execute or block — evidence preserved

Risk advises. Policy decides. Evidence proves.

// APPROVAL GATE

Production-touching change or out-of-baseline modification.

// EVIDENCE

Evidence bundle with the change action, policy version, risk advisory context, and approval when required.

// BUSINESS OUTCOME

Pre-execution control over production changes — not reactive log review.

Pilot

Pilot this guard

Start with a protected workflow pilot — shadow first, gate when ready.