Modernizing change control with AI and automation to eliminate bottlenecks while maintaining safety and compliance
As a network engineer and later as an enterprise architect, I spent a lot of time in those rooms:
Environments where you had to submit a change two weeks in advance, present it to a panel, fix whatever they didn't like, and if you missed your resubmission window you were waiting another few weeks.
ARBs that met weekly and moved quickly.
ARBs that met once a month and became a parking lot for every controversial idea.
And then there were the "emergencies."
One of the most frustrating experiences I had was an emergency change that was time‑critical and dependent on another high‑level request. I convened an emergency CAB (eCAB), walked through exactly what was going to happen, and was very confident I could contain the impact. Most of the people in the room agreed and were ready to approve.
Except one.
The blocker wasn't that the change was reckless. It was that this one person didn't understand the technical approach and didn't want to be accountable if something went wrong. I understood where he was coming from, but it was surreal to be unable to execute a solid, time‑sensitive plan simply because one person didn't feel comfortable enough with the details.
When we finally got approval later, the approach worked exactly as designed. But the delay, the friction, and the feeling of being blocked by fear and lack of understanding, not by actual risk, is the kind of thing that made me despise traditional change control.
Speed. Every layer of review added safety, but also latency, meetings, and human overhead. And in many orgs, ARBs turned into exactly what they were supposed to prevent: logjams and political arenas instead of collaborative design reviews.
Now that I'm spending more time in the software world, and watching what's possible with modern CI/CD and AI, I'm convinced we can do better:
This is a how‑to for modernizing change control.
The question isn't "should we have governance?" It's:
Modern CI/CD and AI give us a path.
As you work on a change, automation and AI:
Humans only step in where judgment is actually needed.
We're not abolishing governance; we're moving it closer to the code and letting machines handle the boilerplate.
Not all changes deserve the same process.
Create a simple risk taxonomy, for example:
Low risk, well‑understood, repeatable:
Moderate risk:
Potentially large blast radius:
Most CAB/ARB forms are checklists in disguise:
Instead of asking humans to retype these answers every time, do this:
CI pipeline checks:
Infra checks:
For example, Open Policy Agent (OPA) or custom rules that say:
Now the "checklist" is mostly automated gates, not a PDF.
For each change, an LLM can assemble a change brief automatically from:
The PR description and diff.
Linked tickets/issues.
Deployment strategy (from your pipeline config).
Observability setup (from your monitoring config).
Ownership metadata (who owns this service).
Summarized from the PR and diff.
Pulled from the linked Jira/Linear ticket.
Inferred from which services and data stores are touched.
Derived from your CI/CD config (e.g., canary, blue‑green, feature flags).
Calculated based on your deployment schedule and rollback strategy.
Checked via policy as code and approvals in your tooling.
Instead of humans filling out a form, they review and correct an AI‑generated brief. This way even people who aren't deep in the technology have a clear, structured explanation of what's happening and why, backed by an independent assessment of risk and rollback options.
For high‑risk changes, this brief becomes the input to a short, focused review, not a two‑week process.
Once you have:
You can redesign the human part:
Async review:
Optional quick huddle if something looks risky.
Short, focused review meeting:
A startup with GitHub Actions, ECS, and Sentry:
Standard changes:
Normal changes:
High‑risk changes:
Even as a solo dev, you can benefit from "change control" without bureaucracy:
Every significant change:
A small script or Cursor prompt:
You're forcing yourself to think like a CAB, but the "board" is you plus AI, and the process is minutes, not weeks.
If you just bolt AI onto the existing CAB/ARB calendar, you'll get better paperwork but the same bottlenecks.
Do this instead:
Use AI and automation as a reason to change the process, not just the artifacts:
If everything is high‑risk, nothing is.
Do this instead:
AI can help classify risk, but it doesn't know your regulators, your politics, or your weird legacy systems.
Do this instead:
If people don't trust the new process, they'll route around it.
Do this instead:
Use this as a roadmap, not a test you have to pass on day one.
If you can check most of these, you've kept the spirit of change control: safety, coordination, auditability, while stripping away a lot of the ceremony and delay.
You haven't abolished governance. You've just moved it out of the calendar and into the pipeline, with AI doing the boring parts.
Change Control at Ludicrous Speed: How to Replace Logjams with AI and Keep Governance Without the Drag