Change Guard is the path a production change takes: scored for risk, authorised by policy or by a person, executed through the automation you already run, verified against your monitoring, and rolled back when it did not work. Autonomy is earned per class of change, on its success record.
An agent or a person raises the change, attached to a change record in your ticketing tool.
Risk from what it touches, the history of similar changes, the incidents around it and the data behind it.
A pre-approved class goes straight through; anything else waits for the right approver.
Through your automation — playbooks, runbooks, infrastructure as code, cluster APIs — never around it.
Against your monitoring: did the service stay healthy and did the change do what it said?
If not, the rollback runs and the record says why — for the change board and the auditor.
Your change board decides which classes of change are pre-approved. Each class starts under approval and is promoted on its own record — success rate, zero attempts outside its bounds, rollbacks under the threshold — and demoted when that record slips. The board spends its time on the changes that deserve it.
Your own operations team runs Change Guard. See every offer · Agent Fleet Guardian