How it works
The workflows, end to end
Five workflows cover everything the app does. None of them asks anyone to leave the issue they are working on.
The change lifecycle
A change moves through five governance states. The rules are enforced in the backend, so they hold whether somebody clicks a button, uses a keyboard, or crafts the request by hand. Rejected is the end of the road; approved is the end for any person, but an approval covers the dates it was given for, and the system will take one back.
1. Recording a change
An agent opens any Jira issue in a project where Concessa is set up and fills in the panel. Nothing is written to the audit trail until they do — an issue nobody has recorded governance for is simply not governed, and the panel says so rather than pretending otherwise.
- 1
Open the issue
The Concessa panel appears on every issue in an enabled project.
- 2
Record the details
A summary of what is changing and why — the one required field — then risk, change type, impacted service and the planned window. Times are read in your own timezone.
- 3
The chain records it
A
change.recordedentry is appended before the record is written, so a failure can never leave a change nobody recorded.
2. The approval round
- 1
Ask a named agent
Pick from the people Jira says can be assigned this issue — so a candidate can never be somebody with no business seeing it. You cannot pick yourself.
- 2
Jira notifies them
A comment goes on the issue and your own notification scheme does the rest. The app sends no mail of its own.
- 3
They decide, once
Only the named approver sees Approve and Reject. A comment is optional; the decision and comment both go on the chain.
- 4
The change moves
A rejection sends the change back rather than leaving it in review looking like it might still pass. Full approval unlocks the approved state — if no freeze blocks it.
- 5
And can move back
An approval is permission to make that change at that time. Move the planned dates outside the window it was approved for and Concessa withdraws the approval, returns the change to review and asks its approvers again — on the chain, and with a comment on the issue so nobody finds out by accident.
3. Freeze windows and overrides
A project administrator declares a window with a name, dates and a reason. Every change already scheduled inside it is re-checked and flagged there and then.
- 1
Declare the window
From Project settings → Concessa. Existing changes inside it are marked freeze conflict immediately.
- 2
The change is blocked
It cannot be approved. The panel names the window and its reason, so nobody has to go and look up why.
- 3
Reschedule, or override
Moving the change out clears the conflict by itself — though if the change was already approved, moving it outside its approved window withdraws that approval too. Otherwise a project administrator records an override with a written reason.
- 4
The override is narrow
It is bound to the window it was granted for. Move the change into a different freeze and the conflict is raised again; move it clear of every freeze and the override retires. Rescheduling inside the same window keeps it.
4. Running the CAB
Open the CAB workbench. If an administrator has set a cadence, this week’s meeting is already there — nobody types a date into a calendar. Open it, mark who came, and work down the agenda: the standing items your board always covers, then the changes attached to the meeting.
Approvals are still given from the issue panel, one change at a time, so the meeting ends with decisions recorded rather than actions to write up afterwards. What the meeting itself records is the rest: who was there, what was discussed, and what somebody agreed to do about it.
Below the meetings sits the change agenda, ordered deliberately: what needs you, then what is blocked, then risk, then imminence. Each change key opens the issue in a new tab, so the agenda and the filter you were on stay behind it.
5. Taking evidence
When an auditor asks, open Evidence, choose a scope and a format, and take the export. The chain is re-verified from genesis at that moment and the verdict is written into the file.
Put change governance where the work already happens
Concessa is a pure Forge app, charged per agent. No external systems, no data leaving your site, nothing to host. Access starts with a conversation.