{
  "slug": "who-approved-this-deploy",
  "title": "Who approved this deploy? The audit log says the pipeline did.",
  "summary": "A pull request approval is a click in a session. Why change management evidence proves a workflow ran, not that a person decided, and what a signed deploy fixes.",
  "lede": "Every change management control in a modern engineering organisation proves that a workflow ran and that a session clicked. None of them proves that a person decided. As agents write, review and merge a growing share of production changes, that gap stops being a philosophical curiosity and becomes the thing your auditor asks about.",
  "date": "2026-09-17",
  "reading_time": "18 min read",
  "category": "Standards",
  "tags": ["change management", "SOC 2", "CC8.1", "deployment approval", "CI/CD", "separation of duties", "audit evidence"],
  "image": "https://cdn.twc.sh/images/igcache/Deploy%20Approval%20Provenance/1200_630/blog.jpg",
  "url": "/blog/who-approved-this-deploy.html",
  "wordcount": 4643,
  "related": ["human-signed-publish", "agent-deleted-production", "identity-failure-map"],
  "schema": "Article"
}
