Skip to content
Changefy Research — State of Governed AI Operations 2026Read it
Changefy

CHANGEFY · GOVERNED AI OPERATIONS

Your AI operations engineer.

Tell Changefy what you need. It investigates your environment, builds a plan, waits for a human to authorize it, executes the work, and proves the result — with a full record of every step.

  • Policy enforced
  • Human authorized
  • Evidence captured
  • Infrastructure agnostic
Changefy work item WRK-2041 stepping through investigate, diagnose, plan, review, execute, verify, and audit for a GCP-to-Sentinel logging incident

FROM INTENT TO VERIFIED CHANGE

Seven steps between a request and a proven outcome.

  1. Investigate
  2. Diagnose
  3. Plan
  4. Review
  5. Execute
  6. Verify
  7. Audit

Traditional AI says

“I’ve restarted the log forwarder — it should be working now.”

Changefy did

Re-granted the IAM role, redeployed the sink, restarted the forwarder, and confirmed a live event reached Sentinel 42 seconds later. Recorded in evidence req_9f23.

01 · INVESTIGATE

Understand the estate before touching it.

Changefy pulls real context from the systems involved — not just the request text — before it forms an opinion about what’s wrong.

  • Infrastructure context
  • Configuration state
  • Logs
  • Metrics
  • Dependencies
  • Recent changes
  • Policies
  • Ownership
Changefy correlated sources panel showing live status across GCP Cloud Logging, Microsoft Sentinel, GitHub, and Datadog
Changefy reasoning timeline correlating a deploy with a p99 latency spike and identifying a connection pool regression at 92% confidence

02 · DIAGNOSE

Say what’s wrong, and how sure you are.

For the payments p99 regression, Changefy correlated deploy 2c1f4a with the latency spike and identified a connection-pool sizing regression as the root cause, at 92% confidence — stated as a number, not a guess dressed up as certainty.

03 · PLAN

Every plan carries its own risk profile.

Changefy doesn’t just propose actions — it scores them. Risk level, blast radius, rollback path, and the exact checks that will prove success, all before a human ever sees an approval request.

If reality drifts from the plan mid-execution, Changefy stops and asks — it doesn’t improvise past what was authorized.

Changefy plan panel for WRK-2841 showing risk, environment, blast radius, policy, rollback, and verification checks

04 · REVIEW

AI proposes.
Humans authorize.

  • Every production-risk plan requires an explicit approval.
  • Approvers see the full plan, not a summary.
  • Requests can be approved, sent back for changes, or rejected.
  • Approval policy is configurable per environment and per risk level.
Changefy approval request for WRK-2041 showing risk, environment, requested actions, approver, and Approve, Request changes, and Reject controls

05 · EXECUTE

Watch it happen, step by step.

Execution runs the authorized plan one step at a time against real systems, streaming a live log — with an abort control always visible.

Changefy execution log streaming through IAM grant, sink redeploy, forwarder restart, and event confirmation steps

06 · VERIFY

Don’t trust the AI because it says it worked.
Make it prove it.

Changefy before and after verification comparing the Sentinel connector status, error rate, and status before and after the fix

07 · AUDIT

Every AI action. Accounted for.

Changefy evidence timeline for WRK-2041 recording every actor, system, action, and result from investigation through verification

USE CASES

Real operational work, end to end.

01

Cloud incident: GCP logs stop reaching Sentinel

Changefy traces a broken log pipeline back to an IAM rotation, drafts the fix, and confirms events are flowing again.

sink=log-forwarder · status=VERIFIED · lag=42s

02

Resize an undersized production VM

Investigates CPU pressure, proposes a resize window, executes with a rollback snapshot, and verifies headroom afterward.

vm=api-worker-03 · size=D4s→D8s · risk=LOW

03

Tighten an overly permissive firewall rule

Finds a rule open to 0.0.0.0/0, plans a scoped replacement, and verifies no dependent service loses connectivity.

rule=allow-any-8443 · blast_radius=2 services

04

Ship a GitHub change to Azure

Picks up a merged PR, plans the deployment, waits for approval, executes the release, and verifies health checks pass.

pr=#4821 · env=production · rollout=canary

05

Expand a SAN LUN before it fills

Diagnoses disk growth trend, plans a capacity expansion with a maintenance window, and verifies free space afterward.

lun=vol-9c2 · free=4% → 38%

06

Chase down payments p99 latency

Correlates a deploy with a latency regression, proposes a connection-pool fix, and verifies p99 returns to baseline.

deploy=2c1f4a · p99=840ms → 210ms

07

Contain a Sentinel security alert

Investigates a suspicious sign-in alert, plans a scoped containment action, and verifies the session is terminated.

alert=SEN-8842 · action=revoke session

08

Run a staged patching cycle across a host fleet

Patches dev a week ahead of production, drains sessions in capacity-preserving batches, and verifies every host healthy before closing the window — planned maintenance, not firefighting.

hosts=52 · batches=2 · min_capacity=50%

CONNECTIONS

Plugs into the estate you already run.

View all integrations →

Cloud

  • Azure — Available
  • AWS — Available
  • Google Cloud — Beta

Observability

  • Datadog — Available
  • Sentinel — Available
  • Grafana — Beta
  • Prometheus — Beta

Source control

  • GitHub — Available
  • GitLab — Planned

Infrastructure

  • Terraform — Available
  • Kubernetes — Beta
  • VMware — Planned

IT / Ops

  • ServiceNow — Beta
  • Jira — Planned

ARCHITECTURE

Autonomous where it should be.
Constrained where it must be.

  • Least privilege on every credential Changefy holds
  • Scoped, short-lived credentials per execution
  • Policy enforcement before a single action runs
  • Human approval gates on anything above low risk
  • Hard execution boundaries per environment
  • Immutable activity history for every work item
  • Secrets stay inside the execution environment
  • Stop-on-deviation the moment reality departs from the plan

WHY CHANGEFY

A copilot suggests. An agent might act. Changefy proves it.

CapabilityTraditional CopilotAI AgentChangefy
Understands the requestYesYesYes
Investigates real infrastructureNoPartialYes
States a diagnosis with confidenceNoSometimesYes
Produces a risk-scored planNoRarelyYes
Requires human authorizationN/AOptionalAlways
Executes against real systemsNoSometimesYes
Stops on deviation mid-executionNoNoYes
Verifies the outcome independentlyNoNoYes
Produces an exportable evidence trailNoNoYes

INSIDE CHANGEFY

Changefy work console showing the Work list with WRK-2041 restore Sentinel log flow verified, WRK-2038 resize api-worker-03 awaiting approval, and WRK-2032 payments p99 regression investigating

CHANGEFY

Tell Changefy what needs to happen.
Let AI do the operational work.

Investigate. Plan. Authorize. Execute. Verify.