Agent skill

Change Management

by Hack23 in Hack23/cia

Secure change control: RFC process, testing requirements, rollback procedures per ISO 27001 A.8.9, A.8.32

Apache-2.0Auto-check passedLegal & Compliance

Install Change Management

skills CLI
$ npx skills add Hack23/cia --skill change-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia change-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/change-management .claude/skills/change-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
change-management
GitHub stars
239
Token cost
~3k tokens
SKILL.md length
695 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Secure change control: RFC process, testing requirements, rollback procedures per ISO 27001 A.8.9, A.8.32

  • Tasks that involve SOC 2 and security compliance
  • SKILL.md covers Purpose, When to Use This Skill, Change Categories and Git Workflow Integration, plus 8 more sections
  • Calls psql, pg_dump and curl

What it does

Change Management is an agent skill from Hack23/cia. Secure change control: RFC process, testing requirements, rollback procedures per ISO 27001 A.8.9, A.8.32

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Legal & Compliance, covering SOC 2 and security compliance. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve SOC 2 and security compliance

Example prompts

  • “/change-management”

Requirements

  • Node.js

What it can do on your machine

Read from SKILL.md and the folder at commit 6a9797b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • psql
    • pg_dump
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Change Management loads about 3k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 695 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit 6a9797b, republished under its Apache-2.0 licence (© Hack23). 695 words, ~3,041 tokens.

Download SKILL.mdSave it as .claude/skills/change-management/SKILL.md (or your agent's skills folder).
name
change-management
description
Secure change control: RFC process, testing requirements, rollback procedures per ISO 27001 A.8.9, A.8.32
license
Apache-2.0

Change Management Skill

Purpose

This skill provides systematic guidance for implementing secure change control within the CIA platform, ensuring all changes are documented, tested, approved, and reversible per ISO 27001 A.8.9 (Configuration Management) and A.8.32 (Change Management).

When to Use This Skill

Apply this skill when:

  • ✅ Planning code changes, infrastructure modifications, or system updates
  • ✅ Implementing new features or fixing bugs
  • ✅ Modifying security controls or access policies
  • ✅ Updating dependencies or third-party integrations
  • ✅ Deploying to production environments
  • ✅ Conducting emergency changes for incidents
  • ✅ Reviewing pull requests and change proposals
  • ✅ Managing configuration changes (database schema, infrastructure as code)

Do NOT skip for:

  • ❌ "Minor" changes (all changes require review)
  • ❌ Emergency hotfixes (follow emergency change procedure)
  • ❌ Configuration updates (require approval and testing)
  • ❌ Documentation changes (still require peer review)

Change Categories

🟢 Standard Changes (Pre-Approved)

Definition: Low-risk, routine changes with documented procedures and automated security validation.

Examples:

  • Documentation updates (README, user guides)
  • Test case additions or improvements
  • Code refactoring without behavior changes
  • Dependency patches for non-critical vulnerabilities
  • UI/UX improvements without data handling changes

Requirements:

  • ✅ All automated security checks pass
  • ✅ No critical system components affected
  • ✅ Rollback procedures documented
  • ✅ Changes logged in version control

GitHub Actions Workflow:

yaml
name: Standard Change Validation
# Pinned: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1

on:
  pull_request:
    paths:
      - '**.md'
      - 'docs/**'
      - 'test/**'

jobs:
  validate-standard-change:
    runs-on: ubuntu-latest
    steps:
      - name: Checkout code
        uses: actions/checkout@b4ffde65f46336ab88eb53be808477a3936bae11 # v4.1.1
      
      - name: Validate documentation
        run: |
          echo "Validating standard change..."
          # Markdown linting
          npx markdownlint-cli2 "**/*.md"
      
      - name: Check for security issues
        run: |
          # Ensure no secrets in documentation
          if grep -r "password\|secret\|key" --include="*.md" .; then
            echo "ERROR: Potential secrets in documentation"
            exit 1
          fi
      
      - name: Auto-approve standard change
        if: success()
        run: echo "Standard change pre-approved - deploy authorized"
🟡 Normal Changes (CEO Review & Approval)

Definition: Medium-risk changes requiring CEO review and explicit approval before implementation.

Examples:

  • New application features
  • Infrastructure modifications (AWS resources, networking)
  • Security control changes
  • Third-party integrations
  • Database schema modifications
  • Agent configuration changes (.github/agents/*.md, .github/copilot-mcp*.json)

Requirements:

  • ✅ All Standard Change requirements met
  • ✅ Business justification documented
  • ✅ Risk assessment completed
  • ✅ Implementation plan reviewed
  • ✅ Success criteria defined
  • ✅ CEO approval obtained

Request for Change (RFC) Template:

markdown
# RFC: [Change Title]

## Change Information
- **RFC ID**: RFC-2025-001
- **Requester**: Developer Name
- **Date**: 2025-02-10
- **Priority**: Normal
- **Category**: Infrastructure

## Business Justification
Why is this change needed? What business problem does it solve?

## Technical Description
Detailed technical description of the change.

## Risk Assessment
| Risk Category | Level | Mitigation |
|---------------|-------|------------|
| Security | Medium | Security review completed |
| Availability | Low | Blue-green deployment |
| Data Integrity | Low | Database backup before migration |

## Testing Plan
- [ ] Unit tests pass (80% coverage minimum)
- [ ] Integration tests pass
- [ ] Security scanning clean (CodeQL, OWASP)
- [ ] Performance testing completed
- [ ] Staging environment validation

## Rollback Procedure
1. Identify rollback trigger conditions
2. Steps to revert change
3. Data recovery procedures (if applicable)
4. Estimated rollback time: 15 minutes

## Implementation Schedule
- **Planned Start**: 2025-02-15 10:00 UTC
- **Estimated Duration**: 2 hours
- **Planned Completion**: 2025-02-15 12:00 UTC

## Approval
- [ ] CEO Review
- [ ] CEO Approval
- [ ] Deployment Authorization

**CEO Signature**: ________________  **Date**: __________
🔴 Emergency Changes (Immediate Implementation)

Definition: Critical changes required to restore service availability or address active security incidents.

Triggers:

  • Active security incidents (breach, vulnerability exploitation)
  • Critical service outages (production down, data unavailable)
  • Critical zero-day vulnerabilities

Authorization:

  • ✅ CEO has sole authority for emergency changes
  • ✅ All actions logged with timestamps
  • ✅ Complete documentation within 4 hours
  • ✅ Post-implementation review within 24 hours
  • ✅ Lessons learned integration

Emergency Change Workflow:

mermaid
sequenceDiagram
    participant Inc as 🚨 Incident
    participant CEO as 👨💼 CEO
    participant Impl as 🔧 Implementation
    participant Monitor as 📊 Monitoring
    participant Review as 📋 Post-Review
    
    Inc->>CEO: 1. Incident Detected
    CEO->>CEO: 2. Assess Severity
    CEO->>CEO: 3. Authorize Emergency Change
    CEO->>Impl: 4. Implement Fix
    Impl->>Monitor: 5. Verify Fix Applied
    Monitor->>CEO: 6. Confirm Resolution
    CEO->>CEO: 7. Document Change (4h deadline)
    CEO->>Review: 8. Schedule Post-Review (24h)
    Review->>Review: 9. Lessons Learned

Git Workflow Integration

Feature Branch Workflow
mermaid
gitGraph
    commit id: "main"
    branch feature/new-analysis-tool
    checkout feature/new-analysis-tool
    commit id: "Implement analysis logic"
    commit id: "Add unit tests"
    commit id: "Update documentation"
    checkout main
    merge feature/new-analysis-tool tag: "PR #123 - CEO Approved"
    commit id: "Deploy to production"
Branch Protection Rules
yaml
# .github/branch-protection-config.yml
# Branch protection for main branch

branch-protection:
  main:
    required_status_checks:
      strict: true
      contexts:
        - "build"
        - "test"
        - "security-scan"
        - "codeql-analysis"
    
    required_pull_request_reviews:
      required_approving_review_count: 1
      dismiss_stale_reviews: true
      require_code_owner_reviews: true
      require_last_push_approval: true
    
    restrictions:
      users:
        - "pethers" # CEO - only authorized deployer
      teams: []
    
    enforce_admins: true
    require_linear_history: true
    allow_force_pushes: false
    allow_deletions: false

Rollback Procedures

Database Schema Rollback
bash
#!/bin/bash
# Database schema rollback script

set -euo pipefail

BACKUP_DATE=${1:-$(date +%Y%m%d)}
BACKUP_FILE="/backups/database-${BACKUP_DATE}.sql"

rollback_database() {
  echo "🔄 Starting database rollback..."
  
  # 1. Create pre-rollback backup
  echo "📦 Creating pre-rollback backup..."
  pg_dump -h $DB_HOST -U $DB_USER -d cia_database > "/backups/pre-rollback-$(date +%Y%m%d-%H%M%S).sql"
  
  # 2. Stop application services
  echo "🛑 Stopping application services..."
  systemctl stop cia-application
  
  # 3. Restore from backup
  echo "📥 Restoring database from backup..."
  psql -h $DB_HOST -U $DB_USER -d cia_database < "${BACKUP_FILE}"
  
  # 4. Verify restoration
  echo "✅ Verifying database restoration..."
  psql -h $DB_HOST -U $DB_USER -d cia_database -c "\
    SELECT COUNT(*) as table_count FROM information_schema.tables \
    WHERE table_schema = 'public';"
  
  # 5. Restart application
  echo "🚀 Restarting application services..."
  systemctl start cia-application
  
  # 6. Verify application health
  echo "🏥 Checking application health..."
  curl -f http://localhost:8080/actuator/health || {
    echo "❌ Application health check failed"
    exit 1
  }
  
  echo "✅ Database rollback completed successfully"
}

# Execute rollback
rollback_database

Change Performance Metrics

Key Performance Indicators
MetricTargetMeasurementReview Frequency
Change Success Rate>95%Deployments without rollbackWeekly
Mean Time to Deploy<2 hoursFrom approval to productionMonthly
Rollback Rate<5%Changes requiring rollbackMonthly
Emergency Change Rate<2%Emergency vs total changesMonthly
Change Lead Time<7 daysRFC to deploymentQuarterly
Security Gate Pass Rate100%First-time security scan passWeekly

ISO 27001 Control Mapping

A.8.9 - Configuration Management

Control Objective: Configuration of systems and networks documented and controlled.

Implementation:

  • ✅ Infrastructure as Code (CloudFormation, Terraform)
  • ✅ Configuration version control (Git)
  • ✅ Automated configuration validation
  • ✅ Configuration backup and recovery
Show full SKILL.md (268 more words)Show less
A.8.32 - Change Management

Control Objective: Changes to information processing facilities and systems controlled.

Implementation:

  • ✅ Three-tier change categorization (Standard, Normal, Emergency)
  • ✅ RFC process for Normal changes
  • ✅ CEO approval for Normal/Emergency changes
  • ✅ Automated change classification
  • ✅ Rollback procedures documented and tested
  • ✅ Post-implementation review within 24 hours

NIST Cybersecurity Framework Mapping

PR.IP-3: Configuration change control processes in place

  • ✅ Formal change management process
  • ✅ Version control for all changes
  • ✅ Automated testing and validation

PR.IP-4: Backups of information conducted, maintained, tested

  • ✅ Automated backup before changes
  • ✅ Rollback procedures tested quarterly
  • ✅ Recovery time objectives defined

CIS Controls Mapping

CIS Control 3.14: Log Configuration Changes

  • ✅ All changes logged in Git
  • ✅ AWS CloudTrail for infrastructure changes
  • ✅ Audit trail maintained for minimum 1 year

CIS Control 4.1: Establish and Maintain Secure Configuration Process

  • ✅ Secure configuration baselines defined
  • ✅ Configuration changes reviewed and approved
  • ✅ Automated compliance checking

Practical Implementation Checklist

For Developers
  • Clone repository and create feature branch
  • Make changes following coding standards
  • Add unit tests (80% coverage minimum)
  • Run security scanning locally
  • Create pull request with RFC (for Normal changes)
  • Address code review feedback
  • Obtain CEO approval (for Normal changes)
  • Monitor deployment and verify success
For CEO/Reviewer
  • Review RFC documentation
  • Assess business justification and risk
  • Verify testing completeness
  • Check security scanning results
  • Validate rollback procedure
  • Approve or request changes
  • Monitor deployment
  • Conduct post-implementation review

References

  • ISO 27001:2022 - A.8.9 Configuration Management
  • ISO 27001:2022 - A.8.32 Change Management
  • ITIL 4 - Change Control
  • NIST SP 800-128 - Guide for Security-Focused Configuration Management
  • CIS Controls v8 - Control 3: Data Protection

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. 1 hidden character (zero-width or bidirectional) removed. Raw file

Files

Just SKILL.md in .github/skills/change-management of Hack23/cia.

Open the folder on GitHubat commit 6a9797b

Compare with similar skills

Change Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Change Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Change Management this skillHack23/cia239—~3kAutomated safety check: PassApache-2.0
Trust Center BuilderGRCEngClub/claude-grc-engineering419—~2.6kAutomated safety check: PassCustom licence
Policy OpaAgentSecOps/SecOpsAgentKit2191 repos~3.5kAutomated safety check: PassCustom licence
AWS Inspector ExpertGRCEngClub/claude-grc-engineering419—~1.4kAutomated safety check: PassCustom licence
Nist 800 53Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~3.3kAutomated safety check: PassMIT
Soc2Sushegaad/Claude-Skills-Governance-Risk-and-Compliance9391 repos~2.7kAutomated safety check: PassMIT

Similar skills

  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    219 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • AWS Inspector Expert

    GRCEngClub/claude-grc-engineering

    Expertise in evaluating AWS accounts for compliance — what checks are meaningful, which SCF controls they map to, and how to interpret aws CLI output.

    419 GitHub stars~1.4k tokensUpdated 3 days ago
    Legal & ComplianceAuto-check passed
  • Nist 800 53

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    NIST SP 800-53 Rev 5 compliance advisor — all 20 control families (AC, AT, AU, CA, CM, CP, IA, IR, MA, MP, PE, PL, PM, PS, PT, RA, SA, SC, SI, SR), Low/Moderate/High baseline selection, FIPS 199/200…

    939 GitHub starsUsed in 1 repo~3.3k tokens
    Legal & ComplianceAuto-check passed
  • Soc2

    Sushegaad/Claude-Skills-Governance-Risk-and-Compliance

    Expert SOC 2 compliance assistant covering all five Trust Services Criteria (Security/CC, Availability/A, Confidentiality/C, Processing Integrity/PI, Privacy/P).

    939 GitHub starsUsed in 1 repo~2.7k tokens
    Legal & ComplianceAuto-check passed
  • Grc Knowledge

    mlunato47/claude-grc-plugin

    Senior GRC analyst expertise across 18 compliance frameworks — NIST 800-53, FedRAMP (Rev5 + 20x/CR26, KSIs, VDR/VER, Certification Classes A–D), DoD/DoW Impact Levels (IL2–IL6, DISA Cloud SRG), ITAR…

    183 GitHub stars~6.1k tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated yesterday
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated yesterday
    Auto-check passed

Questions about Change Management

What does Change Management do?

Secure change control: RFC process, testing requirements, rollback procedures per ISO 27001 A.8.9, A.8.32. Change Management is an agent skill from Hack23/cia.

When should I use Change Management?

Change Management fits situations like: tasks that involve SOC 2 and security compliance.

How do I install Change Management in Claude Code?

Run `npx skills add Hack23/cia --skill change-management -a claude-code`. Or copy the skill folder (.github/skills/change-management in Hack23/cia) into .claude/skills/change-management in your project. Claude Code loads it when a task matches its description.

How do I install Change Management in Codex?

Run `npx skills add Hack23/cia --skill change-management -a codex`. Or copy the skill folder (.github/skills/change-management in Hack23/cia) into .agents/skills/change-management in your project. Codex loads it when a task matches its description.

Can I use Change Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill change-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/change-management, .gemini/skills/change-management, .github/skills/change-management and .opencode/skills/change-management in your project.

What does Change Management need to run?

Going by SKILL.md and its folder, Change Management needs the command-line tools its instructions call (psql, pg_dump and curl). Our summary lists: Node.js.

Does Change Management access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Change Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Change Management use?

Change Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Change Management use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Change Management?

Skills that share tags, products or a category with Change Management: Trust Center Builder (GRCEngClub/claude-grc-engineering, 419 stars), Policy Opa (AgentSecOps/SecOpsAgentKit, 219 stars), AWS Inspector Expert (GRCEngClub/claude-grc-engineering, 419 stars) and Nist 800 53 (Sushegaad/Claude-Skills-Governance-Risk-and-Compliance, 939 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Change Management?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 6, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.