Change Control and Integrity Policy
VOIMAR-POL-005 · Version 1.0 · Effective 9 October 2026 · Approved by VOIMAR (Pty) Ltd
Purpose
Every change to a VOIMAR or client system is controlled, recorded and reversible. Services stay reliable, and every action can be traced to a person, an approval and a result. This policy describes the change control and integrity system that VOIMAR has built and uses every day to manage its infrastructure and projects.
Scope
All changes to infrastructure (routers, switches, firewalls, servers, voice platforms and DNS), platforms and code, made by VOIMAR staff, contractors and AI assistants working for VOIMAR. It applies on VOIMAR systems and on client systems that VOIMAR operates.
Risk-tiered changes
Every action falls into one of four tiers. When in doubt, the higher tier applies.
- Tier 0, Observe: read-only checks, logs and reports.
- Tier 1, Routine: small, reversible, pre-approved changes from a standard catalogue. They need a rollback path, a health check before and after, and a change record.
- Tier 2, Production: anything that can affect customers. It needs the approver's yes in their own words, a rollback plan, a health check before and after, and a change record. It is done in an agreed maintenance window.
- Tier 3, People only: handling passwords and keys, moving money, permanently deleting data, or switching off security controls. A person always does these, never an automated tool, and the action is recorded.
One approval, one change
An approval covers one change only. A message passed on by someone else is a request, not an approval, until the approver confirms it.
Every change is recorded
Every change is written to VOIMAR's engineering change log. The record shows who made the change and when, the system, what changed and why, the approval, the rollback path, the health result before and after, and the source-control reference. Changes made by people and changes made with AI assistance are logged separately, so both can be audited. Device configuration changes are also captured automatically.
Health checks before and after
Before and after every change, automated checks confirm that the critical services (websites, voice platforms, customer internet access and routing) are healthy. If a check fails after a change, the change is rolled back first and investigated second. Risky network changes have a backup, safe mode or automatic undo in place before they start.
Independent review
Changes to sensitive areas (authentication, billing, secrets, voice signalling and proxies), and every significant release, pass an independent code and security review before they go live. Each finding gets a reference, an owner and a date, and is tracked to closure.
Live equals source control
What runs in production is kept in source control. All code is in private VOIMAR repositories, mirrored every hour to VOIMAR's own code vault in South Africa. Before every deployment, the live system is compared with source control, and no one deploys over work that is not recorded. Only one person or team deploys a system at a time.
Versions and release notes
Every VOIMAR system shows its version number, and every release has release notes, so staff and customers always know what changed.
Emergency changes
When service is down or under attack, engineers restore service first through a documented emergency procedure, record what they do as they go, and obtain approval within 24 hours.
Projects
VOIMAR projects use the same system. Every project change is recorded, progress reports and acceptance evidence come from the change records, and the client receives the complete record at handover.
Client environments
On client sites VOIMAR applies the same discipline inside the client's own environment. It works through the client's change advisory board (CAB), and where the client requires it, uses tools hosted on the client's own infrastructure, so that nothing leaves the client's network.
Review
This policy is reviewed every year.
