New · Release 2026.04, Multi-tenant audit exports & SLA dashboards now live See changelog →
ITSM · ITIL

Change management with CAB approvals and rollback plans

Plan and control IT changes safely — standard, normal, or emergency — each with a risk rating, implementation plan, rollback plan, and an approval workflow.

Support tickets · 23 open
7 urgent
TKT-2841 · Production DB slowSLA 2h left
Assigned to Rohan · Critical
TKT-2840 · VPN access for new hireSLA 1d left
Awaiting owner approval
TKT-2838 · Email forwarding setupResolved 14m
Auto-resolved by knowledge base
Product proof

Already live in the product

Backed by app modules

Running in production today: change management on the same engine that powers ITSM approvals.

Protected app route: /change-management
How it works

Built around real workflows

Highlights below describe capabilities already present in the protected app behind this page.

Standard, normal (CAB) and emergency change types
Risk and impact scoring
Implementation and rollback plans
Draft → review → approved → scheduled → completed workflow
Workflow

What teams can do here

Step 1
Raise a change request
Step 2
Attach implementation and rollback plans
Step 3
Route through CAB approval
Step 4
Schedule and track to completion
How it works

How it works

01
Raise the change
Create a change with a title, business justification (reason), risk rating (Low / Medium / High) and impact rating, and choose its type: Standard (pre-approved), Normal (needs CAB) or Emergency. Each change is auto-numbered (CHG-00001, CHG-00002…).
02
Attach the plans
Document the implementation plan, rollback plan and test plan, set planned start and end times, and link the affected assets, related incidents and the problem this change resolves.
03
Route through CAB approval
Submitting a Standard change moves it straight to Approved because it is pre-approved; anything else goes to Under Review for the Change Advisory Board. CAB members record a decision with their role and a comment — and recording a CAB decision is an admin-only action.
04
Approve or block
Any single rejection cancels the change; once there is at least one approval and no pending decisions left, the change advances to Approved. Approvals are captured individually so you can see who signed off and why.
05
Schedule, execute and track
Transition the change through Scheduled, In Progress and finally Completed, Failed or Rolled Back — actual start and end times are stamped automatically. A change-calendar view lists upcoming scheduled changes so you can see what is landing and when.
Example

A worked example

Say a hospital group's IT team raises a firewall firmware upgrade as a Normal change, rated High risk, with the appliance asset attached and implementation, rollback and test plans documented up front. On submit it moves to Under Review; the network lead and the security lead each record a CAB decision with a comment. Both approve, so with nothing left pending the change advances to Approved and is scheduled into a 2am Saturday window — visible on the change calendar beside that weekend's other work. Execution moves it to In Progress, stamping the actual start; after verification it is transitioned to Completed. Had the upgrade gone wrong, Rolled Back would have stamped the end for the record.

FAQ

Frequently asked questions

What change types are supported?
Three: Standard (pre-approved, skips the CAB and goes straight to approved on submit), Normal (routed to the Change Advisory Board for review) and Emergency.
How does CAB approval actually work?
When a Normal change is submitted it moves to Under Review. CAB members each record an approved or rejected decision with their role and a comment. A single rejection cancels the change; once at least one approval exists and nothing is left pending, it advances to Approved.
Who is allowed to approve a change?
Recording a CAB decision is restricted to administrators. Reads, creating a change and driving its lifecycle stay open to org members, but the approval decision itself is a privileged action.
Can we plan the rollback before we start?
Yes — a change carries dedicated implementation, rollback and test plan fields, plus planned start and end times, all captured before execution.
How do changes connect to incidents and problems?
A change can link the assets it affects, the incidents it relates to, and the specific problem it resolves — so a permanent fix from root-cause analysis flows through the change process with a full trail.
Is there a change calendar?
Yes. A calendar view returns upcoming scheduled changes that are not yet completed or cancelled, ordered by planned start, so you can see the forward schedule of work.
What states can a change move through?
Draft, Submitted, Under Review (CAB), Approved, Scheduled, In Progress, and then Completed, Failed, Rolled Back or Cancelled. Moving into progress or a terminal state stamps the actual start and end times automatically.

See also: Problem management · CMDB & configuration · Blog: What is patch management? · Blog: The IT asset lifecycle · Incident management

Related

Explore connected offerings

Ship risky changes with the rollback already written

CAB approvals where one rejection stops the train, pre-attached implementation and rollback plans, and a forward change calendar — governance that leaves a who-approved-what trail.