Skip to content
Agent view: plain rendering of this page's content, without interface illustrations.Machine-readable index
Blog

Four controls that make a deployment defensible

2 min readEngineeringGovernance

Branch policy, independent review, automated checks and an audit trail. None of them slow a team down as much as an unexplained production change does.

On a Friday afternoon, a risk model starts producing different numbers in production. Nobody remembers changing it. Digging in, someone finds an adjustment pushed straight to the main branch to fix something else, with no review and no clear record of who authorised it. The technical problem is solved in an hour. Explaining what happened, to whom and why, takes weeks.

That is the real cost of a deployment without controls: not the error, but the impossibility of reconstructing it.

The four controls

  1. Branch policy. The main branch is protected, working branches are short-lived and nobody pushes changes straight to production.
  2. Independent review. The author of a change never approves it. A second person reviews it before it is merged.
  3. Automated checks. Tests, dependency and security scanning and, where relevant, model validation, run on every change and not only before a release.
  4. Audit trail. Who approved what, when and on which version. None of the other three is worth much without evidence that it was followed.

None of them is new or expensive. Git platforms include them in their enterprise editions; what is usually missing is configuring them with judgement and keeping them up over time.

Why supervisors ask for it

Operational risk and information security frameworks agree on three expectations: segregation of duties, formal change management and traceability. ISO/IEC 27001, for example, includes explicit controls on segregation of duties and change management, and financial supervisors expect an institution to show how every version of a system or a model reached production.

The four controls answer exactly that: branch policy and independent review are segregation of duties; automated checks are change management; the audit trail is the evidence.

Where to start

If you have none of them today, start by protecting the main branch and requiring one review per change. Those are two settings that take minutes and close most of the risk. The rest is built on that base.