ATALAIA
  1. Home
  2. Services
  3. Deploy Approvals
10Station 10 · Release & test

Deploy Approvals

Clear rules for who can promote a build, with which roles, and what evidence they look at before production unlocks.

Four environments, four gates

What has to be green before each door opens, and who can open it.

  1. DEVany developer
    • Unit tests green
    • SAST: no blockers
  2. QApipeline only
    • Security test pack green
    • Authorisation matrix passes
  3. STAGINGrelease role
    • DAST clean
    • No open high pentest findings
  4. PRODapprover role + slot
    • Signed image with SBOM
    • IAM review done
    • Change ticket linked

Break-glass: expires in 2 hours, every command logged, reviewed the next working day.

At the gate

Pick a step, or let it play. Every line is what someone in the room actually says.

Step 1Map who can deploy

People, roles, tokens and pipelines that can reach each environment.

ATALAIAWho can push to production right now?

PLATFORMThirty-one people, and four tokens nobody remembers creating.

Leaves the room31 people and 4 tokens can reach prod

Step 2Define the gates

What must be green at each step, and who signs.

ATALAIAEvery step gets a gate. QA needs tests green, prod needs an approver role.

DEV LEADA role, not a named person? People go on holiday.

ATALAIAA role. Two people hold it, and the pipeline checks it.

Leaves the roomDEV → QA → STAGING → PROD, gates defined

Step 3Attach the evidence

Scans, tests and review status shown at the moment of approval.

MANAGERWhen I approve, what am I actually looking at?

ATALAIAScans, tests and pentest status, on the approval itself.

MANAGERPentest green, tests green. Approved for the 14:00 slot.

Leaves the roomEvidence on the approval

Step 4Review the keys

Access to production reviewed before it ships, and on a schedule.

PLATFORMAnd break-glass, when prod is on fire?

ATALAIAIt works, it expires in two hours, and it's reviewed the next morning.

Leaves the roomBreak-glass: 2 hours, logged, reviewed

  • PLATFORM
  • ATALAIA
  • DEV LEAD
  • MANAGER

Before and after

Before

When everyone can deploy, nobody approves. When approvals are a click with no evidence, they are a delay, not a control.

  • Production access is granted per person, not per role
  • Approvals don't show test, scan or pentest results
  • Emergency access never expires
After
  • A promotion flow from DEV to QA to staging to prod
  • Role-based approvals with evidence attached
  • Break-glass access that expires and is logged
  • An IAM review checkpoint before release

Typical shape: Two to three weeks, often alongside the pipeline audit.

Talk it through

A 30-minute call. No slides, no price list, and a next step either way.