Nonprofit service operations guide
Guide 5: Control configuration and release change
Make routine software change reviewable without turning every adjustment into a large project.
Classify the change
Separate standard low-risk changes, normal reviewed changes, urgent restoration, vendor-controlled releases, and major service changes. Match review and evidence to impact instead of using one heavy process for everything.
Record the purpose, owner, affected users and data, dependencies, test evidence, communication, timing, rollback, and acceptance signal.
Protect the approved state
Use nonprofit-controlled accounts, least privilege, environment separation, versioned configuration where available, and a visible change record. Avoid undocumented production fixes that only one person can explain.
Test representative work, permissions, integrations, reports, accessibility, failure, and recovery according to the change's exposure.
Close with evidence
Confirm the expected operating result, monitor the agreed window, update documentation, and record exceptions or follow-up work. Revert or escalate when the acceptance signal is not met.
Emergency work still needs a retrospective record. Speed changes when evidence is captured, not when accountability disappears.