Version 1.0 · Draft · Owner: Engineering Lead
Download .md →Touch2Sign Ltd
Version: 1.0
Effective date: 11 July 2026
Owner: Robert — Engineering Lead
Approved by: Robert — CEO / Managing Director
Next review: 11 July 2027
Ensure that changes to Touch2Sign production systems are planned, approved, tested, documented, and reversible. Supports SOC 2 CC8 change management criteria and reduces outage and security risk.
Applies to changes affecting:
docs/MIGRATIONS.md) Excludes: routine auto-scaling within configured bounds; Dependabot patch merges following standard PR process (still logged via Git).
| Category | Description | Approval | Lead time | Standard | Pre-approved low-risk changes (dependency patch, copy fix) | 1 engineer + PR review | Same day |
|---|---|---|---|
| Normal | Feature releases, schema migrations, config changes | Engineering Lead | 24 hours notice |
| Significant | Architecture change, new sub-processor integration, IAM policy overhaul | Engineering Lead + Security Lead | 5 business days |
| Emergency | Active incident remediation, Critical CVE patch | Incident Commander | Immediate — retrospective review within 24h |
docs/QA_SIGN_FLOW.md for production-bound releases scripts/rebuild-dev.sh (dev) or scripts/deploy-prod.sh (prod) in agreed window Used when delay would increase harm (active exploit, P1 outage, data exposure):
Every normal and significant change must define rollback before production deploy:
| Change type | Rollback method | Application deploy | Redeploy previous tagged release via deploy-prod.sh |
|---|---|
| Database migration | Reverse migration script or restore from pre-change snapshot |
| Config / feature flag | Revert config in Secrets Manager or feature flag off |
| IAM / security group | Revert to documented previous policy version |
Pre-change RDS snapshot required for schema migrations affecting core tables (documents, audit_log, recipients).
All production changes recorded in the Change Log (ticket system + spreadsheet):
| Field | Description | Change ID | CHG-YYYY-NNN |
|---|---|
| Date/time (UTC) | Implementation time |
| Category | Standard / Normal / Significant / Emergency |
| Description | What changed |
| Requester | Name |
| Approver | Name |
| PR / commit | Link |
| QA reference | QA_SIGN_FLOW checklist ID |
| Rollback performed? | Y/N |
| Outcome | Success / Failed / Rolled back |
| Incident link | If related |
Retention: 3 years minimum.
Standard team (when staff > 1):
Solo operator (current — Robert):
Independent approval is not feasible. Compensating controls per SOLO_TEAM_OPERATING_MODEL.md:
Notify customers when changes:
Reviewed annually and after change-related production incidents.
Approval
| Name | Role | Signature | Date | Robert | CEO / Engineering Lead | Electronic | 11 July 2026 |
|---|
Questions: security@touch2sign.com · privacy@touch2sign.com