Skip to content
Concessa logo: a white faceted C on a rose tile Concessa by ITSM Ltd
Menu

A pure Forge app · zero external systems

Change governance that lives inside Jira

Auditable change records, real approvals, freeze windows and a tamper-evident audit trail — on the Jira issues your team already works. Nothing to host. Nothing leaves your Atlassian site.

Charged per agent · No plans, tiers or paid extras

The Concessa panel on a Jira issue, showing status, risk and change type lozenges, a verified audit chain, the summary of the change, the impacted service and planned window, two approvals with one awaiting a decision, and the issue's audit trail.
The whole change record, on the issue it governs.

Change management fails the same way everywhere

It lives somewhere else

A separate tool means a second record that has to be kept in step by hand — so it isn't. The change ships from Jira and the governance record describes something that didn't happen.

Approvals are theatre

A field somebody types their own name into is not an approval. If the person doing the change can record their own sign-off, the audit finding is already written.

The trail can be edited

A history anyone with admin rights can quietly change is a history nobody can rely on. Evidence has to prove it hasn't been touched, not merely assert it.

Concessa fixes all three by refusing to be a separate system. The Jira issue is the change record. Governance is added on top of it, and the trail is chained so that altering it is detectable.

What you get

The change record

A summary of what is changing, its risk, change type, impacted service and the planned window, on the Jira issue itself. Not a copy of it in another system.

Approvals that mean something

Ask a named agent. Only they can answer, once. Self-approval is refused outright rather than merely flagged.

Freeze windows

Declare a freeze and every change already booked into it is flagged. Approval is blocked until it moves or an administrator overrides — on the record.

A CAB that keeps its own record

Meetings on a cadence, with attendance, an agenda and the actions they raised — above an agenda ordered by what you owe an answer on.

Tamper-evident audit trail

Every action appends a hash-chained entry. Alter one, re-point one, or remove one and verification says so.

Evidence on demand

Export the whole governance record, re-verified from genesis at the moment you take it, in JSON or CSV.

The part your security team cares about

Nothing leaves your Atlassian site

Concessa is a Forge app with no external permissions declared. That is not a policy we promise to keep — it is a property Atlassian enforces. Without an external permission in the app's manifest, the platform refuses an outbound call before it is made.

No external database

Your governance data lives in Forge storage, inside your own Atlassian site, in the region you chose with Atlassian.

No mail transport

Notifications are Jira’s, under your own notification scheme. The app sends no email.

No telemetry

No analytics, no error tracker, no beacon. The app has no way to send anything anywhere.

No vendor access

There is no operator console, no support impersonation and no query path. If we need to see something, you show us.

The part an auditor cares about

A trail you can check, not one you have to believe

Governance evidence is only worth the confidence you can place in it. Every action Concessa records is appended to a per-project hash chain, and every export re-verifies that chain from genesis before it says a word about what happened.

Project OPS · audit chain

  1. change.recorded Ada Lovelace
  2. approval.requested Ada Lovelace
  3. approval.granted Grace Hopper
  4. change.details.updated Sam Ellis
  5. approval.rescinded Concessa

Project chain verified 48 of 48 entries intact, recomputed from genesis.

Each entry hashes its own contents together with the hash of the entry before it. Alter one, re-point one or remove one and every entry after it stops matching — which is what verification reports, and what an export says in its first lines.

Built for the meeting, not the spreadsheet

Set the cadence once and the board’s meetings appear by themselves, each carrying its attendance, its agenda and the actions it raised. Marking one held seals all three and comments on every change it reviewed.

The CAB workbench's next-meeting card and meetings table, each row carrying a date, a status, an attendance summary and a count of attached changes.
The meeting the board is about to hold, above every one it has held.

And an agenda that knows what you owe

Below the meetings, the change agenda puts what needs you at the top, then what is blocked by a freeze, then risk, then whatever is happening soonest.

The CAB workbench listing changes with risk, type, planned window, approval progress and status. Two rows are marked as awaiting the viewer, and one shows a freeze conflict.
The change agenda, filtered to everything awaiting the person looking at it.

A freeze that actually holds

Declare a window and every change already scheduled inside it is flagged straight away. Approval is blocked until it is rescheduled — or a project administrator records an override, with a reason, on the audit trail.

The change calendar for December 2026. The year-end freeze from 20 December is shaded across the grid. Each change is a block coloured by its risk, naming its risk and status and running across every day of its planned window; one change inside the freeze is marked with a warning, and a busy day says how many more it is hiding.
The year-end freeze shaded, every change a bar the length of its window, and the one sitting inside the freeze flagged.

Put change governance where the work already happens

Concessa is a pure Forge app, charged per agent. No external systems, no data leaving your site, nothing to host. Access starts with a conversation.