Bu üç veritabanı yönetilen hedef sistemlerdir. Ürünün kendi kayıt veritabanı SQL Server üzerinde çalışır. These three are the managed target systems. The product keeps its own records on SQL Server.
Büyük ihtimalle doğru. Değişiklik yönetimi, onay akışı ve dağıtım hattı çoğu kurumda gerçekten çalışıyor. Aşağıdaki üç soru, o sürecin tam olarak nerede bittiğini gösterir.It is probably true. Change management, approvals and a delivery pipeline really do work in most organisations. These three questions show exactly where that process ends.
Dağıtım hattı taşıdığını bilir, taşımadığı hakkında sessizdir. Sessizlik "hiçbir şey olmadı" diye okunur. Bu oranı hesaplayan bir yer yoksa cevap tahmindir.A pipeline knows what it carried and stays silent about what it did not. Silence reads as "nothing happened". If no system computes this share, the answer is a guess.
Değişiklik tarafı yönetiliyor olabilir. Okuma tarafı çoğu kurumda hiç yönetilmiyor. Kişisel veri de en çok oradan çıkıyor.The change side may well be governed. The read side is usually not governed at all, and that is where personal data leaves.
Cevap sıfırsa kontrol eleme yapmıyor demektir. Onay, hayır diyebildiği ölçüde onaydır ve reddin kaydı denetimde ayrıca sorulur.If the answer is zero, the control is filtering nothing. An approval is only an approval to the extent that it can say no, and auditors ask for the record of rejections separately.
Bu üç sorunun cevabı bilet sisteminizde, dağıtım hattınızda veya veritabanı günlüğünüzde durmuyor. Hiçbirinin görev tanımında değil. SQL Change Guard tam olarak bu üç soruyu cevaplamak için var.The answers to these three questions do not live in your ticketing system, your pipeline or your database log. They fall outside every one of those remits. SQL Change Guard exists to answer exactly these three.
Kurumunuzun kendi ağına kurulan bir yönetişim katmanıdır. Üretim veritabanlarınız ile onlara dokunan insanlar arasında durur. Çalıştırılacak her betiği ve üretimden veri isteyen her talebi, iş gerçekleşmeden önce yazılı bir kurala göre değerlendirir, politikanın gerektirdiği onaylardan geçirir ve geriye sonradan kanıtlanabilir tek bir kayıt bırakır. Bu yaklaşımın adı Database Operations Governance: yalnız veritabanı değişikliğini değil, üretim verisine erişimi de aynı çatı altında ele alır.It is a governance layer installed inside your own network. It sits between your production databases and the people who touch them. Every script that will run and every request for production data is assessed against a written rule before the work happens, passed through the approvals the policy requires, and left behind as one record that can be proved later. The name for this approach is Database Operations Governance: it covers not only database change but production data access under the same roof.
Kimin için: üretim veritabanlarında değişiklik ve veri erişimi kararlarının kayıtlı olması gereken kurumlar. Şu dört soruyla kendinizi ölçebilirsiniz.Who it is for: organisations that need change and data access decisions on production databases to be on the record. Four questions let you measure yourself.
İkisine "hayır" diyorsanız bu katman sizin için. Dördüne birden "evet" diyebiliyorsanız zaten kurmuşsunuz demektir.If two of them are a no, this layer is for you. If all four are a yes, you have already built it.
Ne değildir: dağıtım aracı değildir, bilet sistemi değildir, izleme ürünü değildir, veritabanı yönetim aracı değildir. Jira, ServiceNow, CI/CD hattınız, Liquibase ve log platformunuz yerinde kalır. Bu katman onların yerine geçmez; hiçbirinin görev tanımında olmayan soruyu cevaplar.What it is not: not a deployment tool, not a ticketing system, not a monitoring product, not a database administration tool. Jira, ServiceNow, your CI/CD pipeline, Liquibase and your log platform all stay where they are. This layer does not replace them; it answers the question that falls outside every one of their remits.
Değişiklik yönetimi var. Onay akışı var. CI/CD var. Log var. Yılda iki kez denetim var. Hepsi çalışıyor, hepsi ayrı sistemde.
Change management is in place. Approvals are in place. CI/CD is in place. Logging is in place. An audit happens twice a year. All of it works, and all of it lives in a different system.
Değişiklik onayı bir sistemde, veri erişimi başka bir sistemde, denetim kanıtı üçüncü bir sistemde. Denetçi geldiğinde altı ayrı yerden ekran görüntüsü toplanıyor.
Change approval lives in one system, data access in another, audit evidence in a third. When the auditor arrives, screenshots are collected from six places.
Kimse yanlış bir şey yapmadı. Sadece hiç kimse bütünün sahibi değil.
Nobody did anything wrong. It is just that nobody owns the whole.
Cevap kurumda vardır. Sorun, cevabın dört ayrı sistemde parça parça durmasıdır. Her parçayı elle eşleştirmek zaman alır ve bu süre her denetimde yeniden ödenir.The answer exists inside the organisation. The problem is that it sits in four separate systems in pieces. Matching those pieces by hand takes time, and that time is paid again at every audit.
Korelasyon vergisi:The correlation tax: Tek bir soruya cevap vermek için dört sistemin zaman damgalarını elle eşleştirmek gerekir. Bu emek denetim başına ödenir, kanıt olarak ekran görüntüsü bırakır ve eşleşme hiçbir zaman tam olmaz. Answering a single question means lining up timestamps across four systems by hand. That effort is paid per audit, it leaves screenshots as evidence, and the match is never complete.
Sonuç:The outcome: Denetçinin sorusu bir talep numarasına iner. Kanıt işin kendisinden üretilir, denetim için ayrıca hazırlanmaz. The auditor's question comes down to one request number. The evidence is produced by the work itself rather than prepared for the audit.
| Denetçinin sorusuThe auditor asks | Dağınık kurulumda cevabı neredeWhere the answer lives when tooling is scattered | SQL Change Guard ileWith SQL Change Guard |
|---|---|---|
| Bu değişikliği kim istedi?Who asked for this change? | Bilet sisteminde, betiğin son haline bağlı değilIn the ticket, not linked to the final script | Talep kaydında, betikle birlikteOn the request, together with the script |
| Hangi kural gereği onaya gitti?Under which rule did it go for approval? | Çoğu zaman hiçbir yerde, alışkanlığa bağlıUsually nowhere; it follows habit | Talebe dondurulmuş o günkü kural setiThe rule set of that day, frozen onto the request |
| Çalışan metin onaylanan metin miydi?Was the text that ran the text that was approved? | Karşılaştırma elle yapılır, çoğu zaman yapılmazCompared by hand, and usually not at all | Betiğin parmak izi kayıtta dururThe script fingerprint stays on the record |
| Üretim verisini kim, hangi gerekçeyle okudu?Who read production data, and why? | Erişim izleme aracında; gerekçe sohbetteIn the activity monitor; the reason is in a chat thread | Sorgu talebinde: gerekçe, maskeleme kararı ve teslim adresiOn the query request: the reason, the masking decision and the delivery address |
| Kaydın kendisi değiştirilmiş olabilir mi?Could the record itself have been altered? | Kaydı tutan ekibin yetkisine güvenilirIt rests on trusting the team that keeps the record | İmzalı iz, ayrı veritabanında mühürlü kopya ve doğrulama düğmesiA signed trail, a sealed copy in a separate database and a verify action |
Bir şeyi değiştirmek ile bir şeyi okumak farklı risklerdir. Ürün ikisini ayrı akış olarak yönetir.Changing something and reading something are different risks. The product handles them as two separate flows.
Şema veya veri değiştiren her betik.Every script that changes schema or data.
Canlı ortamdan veri okuma talepleri.Requests to read data from the live environment.
Bir talep. Baştan sona izlenebilir bir yaşam döngüsü.One request. One lifecycle you can follow end to end.
Kural acele edildiğinde de işler. Asla atlanamaz işaretli bir kural tetiklendiğinde makine talebi kendi başına çalıştıramaz ve o kurala bağlı onay adımı atlanamaz. Kurulumda altı kural bu şekilde işaretlidir. The rule holds even under pressure. When a rule marked never skip is triggered, the machine cannot execute the request on its own and the approval step tied to that rule cannot be skipped. Six rules ship marked this way.
Ne yapar:What it does: Talep açma, çoklu betik, gerçek dilbilgisiyle ayrıştırma, risk bandı, kontrollü çalıştırma, zamanlanmış çalıştırma, geri alma betiği üretimi, izole sunucuda deneme ve sürüm paketi.Request creation, multiple scripts, real grammar parsing, risk banding, controlled execution, scheduled execution, rollback script generation, sandbox trial and release packages.
Neden önemli:Why it matters: Üretime giden betik, kimsenin masasında beklemeden aynı kapıdan geçer ve ne olduğu sonradan okunabilir.A script bound for production goes through the same gate every time, and what happened stays readable afterwards.
AyrıntıDetailsNe yapar:What it does: Sunucu, ortam ve talep tipine göre politika seçimi; kural anahtarı veya risk bandıyla tetiklenen adımlar; kritik nesne tanımları; atlanamaz adım kilidi; görevler ayrılığı parametreleri.Policy selection by server, environment and request type; steps triggered by rule key or risk band; critical object definitions; non skippable step locks; separation of duties parameters.
Neden önemli:Why it matters: Onay bir alışkanlık değil, yazılı bir kural haline gelir. Kuralın o günkü hali talebe dondurulur.Approval stops being a habit and becomes a written rule. The rule as it stood that day is frozen onto the request.
AyrıntıDetailsNe yapar:What it does: Sorgu talebi, hassas kolon tespiti, tam ve kısmi maskeleme, maskesiz kolon için gerekçeli ek onay, şifreli paket teslimi, alıcı adres onayı ve maskeleme denetim kaydı.Query requests, sensitive column detection, full and partial masking, justified extra approval for unmasked columns, encrypted package delivery, recipient address approval and a masking audit record.
Neden önemli:Why it matters: "Şu sorguyu çalıştır, sonucu bana at" cümlesi kayıt altına alınmış bir sürece dönüşür."Run this query and send me the result" turns into a recorded process.
AyrıntıDetailsNe yapar:What it does: İmzalı denetim izi, ayrı veritabanında mühürlü ikinci kopya, veritabanı seviyesinde tetikleyici kaydı, talep bazlı kanıt dosyası, 31 hazır rapor ve nesne değişiklik geçmişi.A signed audit trail, a sealed second copy in a separate database, database level trigger records, a per request evidence file, 31 built in reports and object change history.
Neden önemli:Why it matters: Denetim hazırlığı bir projeye dönüşmez. Kanıt işin kendisinden üretilir.Audit preparation stops being a project. The evidence is produced by the work itself.
AyrıntıDetailsYukarıdaki yeteneklerin bir kısmının kurumunuzda başka bir karşılığı zaten vardır. Aşağıdaki dördünün genellikle yoktur ve bu dördü, ürünün var olma sebebidir.Some of the capabilities above already have a counterpart in your organisation. These four usually do not, and they are the reason the product exists.
Değişiklik tarafında çoğu kurumun bir süreci vardır. Üretimden veri okuma tarafında neredeyse hiçbirinin yoktur. Bilet sistemi okuma taleplerini taşımaz, dağıtım hattı taşımaz, izleme aracı sorgunun çalıştığını görür ama gerekçesini ve dosyanın kime gittiğini görmez.On the change side most organisations have a process. On the side of reading production data, almost none do. Ticketing does not carry read requests, the pipeline does not carry them, and a monitor sees that the query ran but not why, nor where the file went.
Burada talep, gerekçe, hassas kolon tespiti, maskeleme, gerekçeli maskesiz onay, şifreli teslim ve onaylı alıcı adresi tek kayıtta durur. Kişisel veri denetiminde sorulan soruların tamamı buradan cevaplanır.Here the request, its reason, sensitive column detection, masking, a justified approval for unmasked columns, encrypted delivery and the approved recipient all sit on one record. Every question asked in a personal data audit is answered from it.
Sorgu yönetişimi →Query governance →Kural setleri değişir. Altı ay önce verilmiş bir kararı bugünkü kuralla açıklamak yanıltıcıdır ve denetimde kabul edilmez. Talep açıldığında o gün yürürlükte olan kural seti kaydın üzerine dondurulur.Rule sets change. Explaining a decision from six months ago with today's rule is misleading and an auditor will not accept it. When a request opens, the rule set in force that day is frozen onto the record.
Bu, sonradan eklenebilecek bir özellik değil, veri modelinde baştan verilmesi gereken bir karardır. Sonradan eklemek geçmiş kayıtları kurtarmaz.This is not a feature that can be bolted on later; it is a decision the data model has to make from the start. Adding it afterwards does not rescue past records.
Denetim ve kanıt →Audit and evidence →Bir talebin tüm yaşam döngüsü mühürlü tek dosya olur. Mühür denetim kaydına yazılır; dosya sonradan verildiğinde özet yeniden hesaplanıp karşılaştırılır. "Kaydı tutan ekibe güvenin" cümlesine gerek kalmaz.A request's whole lifecycle becomes one sealed file. The seal is written into the audit record; hand the file back later and the digest is recomputed and compared. Nobody has to say "trust the team that keeps the record".
Ve dosya kendi aleyhine de yazar: talebi açan kişi kendi talebini çalıştırdıysa bu istisna olarak kayda geçer. Yönetişimin ölçüsü ihlalin hiç olmaması değil, olduğunda görünmesidir.And the file writes against itself: if the requester executed their own request, that is recorded as an exception. Governance is not measured by the absence of violations but by whether they surface.
Örnek dosyayı indirin →Download the sample file →Kurumların çoğunda en az iki veritabanı motoru vardır ve bir motorun üreticisi diğerini yönetmez. Burada SQL Server, PostgreSQL ve Oracle aynı karar modeline girer; her biri kendi gerçek dilbilgisiyle çözümlenir.Most organisations run at least two database engines, and the maker of one does not govern the other. Here SQL Server, PostgreSQL and Oracle all enter the same decision model, each parsed with its own real grammar.
Gerçek dilbilgisi önemlidir: metin araması, yorum satırındaki bir silme ifadesi ile gerçeğini ayırt edemez. Kural ancak ifadenin sözdizim ağacı üzerinde çalıştığında güvenilirdir.The real grammar matters: text matching cannot tell a delete inside a comment from a real one. A rule is only reliable when it runs on the syntax tree of the statement.
Platform →Platform →Kurum içinde kurulur, veriniz dışarı çıkmaz, arayüz ve destek Türkçedir ve uyum belgeleri KVKK diliyle yazılmıştır. Mevcut araçlarınızın nerede bittiğini ayrı bir sayfada karşılaştırıyoruz. It is installed inside your organisation, your data never leaves, and the interface and support are available in Turkish with compliance documents written in the language of local data protection law. We compare where your current tools end on a separate page.
Yukarıdakiler kararın verildiği yer. Kanıt ise bir ekran değil, bir dosya: bir talebin tüm yaşam döngüsü mühürlü tek dosya olarak dışa aktarılır ve denetçiye o dosya verilir. İçinde kim istedi, o gün hangi kural seti yürürlükteydi, zaman çizelgesi, betiğin parmak izi, risk gerekçesi, maskeleme kararı ve doğrulanmış denetim kayıtları vardır.The screens above are where the decision is made. The evidence is not a screen but a file: a request's whole lifecycle exports as one sealed file, and that file is what the auditor receives. It holds who asked, which rule set was in force that day, the timeline, the script fingerprint, the risk rationale, the masking decision and the verified audit records.
Ürünün gerçek çıktısıdır, tanıtım için hazırlanmış örnek değildir. Kayıt olmadan indirip inceleyebilirsiniz.It is real product output, not a mock-up made for a brochure. You can download and inspect it without signing up.
Slayt yok, ürünün kendisi. Üç sütun için üç akış: üretime giden bir değişiklik, denetçinin eline geçen kanıt ve üretimden çıkan veri.No slides, the product itself. Three flows for the three pillars: a change going to production, the evidence the auditor receives and data leaving production.
Bir kolon ekleme talebi, açıldığı andan üretimde göründüğü ana kadar. Bir buçuk dakika, sessiz, anlatım ekrandaki metinle. Videodaki her ekran ürünün gerçek çıktısıdır.A request to add a column, from the moment it is opened to the moment it appears in production. A minute and a half, silent, narrated by on-screen text. Every screen in it is real product output.
Kanıt denetim için ayrıca hazırlanmaz, işin kendisinden çıkar ve ürün olmadan da doğrulanır.Evidence is not prepared separately for the audit. It comes out of the work itself and can be verified without the product.
Değişiklik çoğu kurumda kontrol edilir, okuma edilmez. Bu akış okuma tarafını gösterir.Most organisations govern changes but not reads. This flow follows the read side.
Kendi sunucunuzda çalışır. Veritabanlarınıza giden yol üzerinde durur, verinizi dışarı taşımaz.It runs on your own servers. It sits on the path to your databases and moves no data outside.
Bilet sisteminiz, hattınız ve log platformunuz yerinde kalır. Ürün bunların yerine geçmez. Your ticketing system, your pipeline and your log platform stay where they are. The product does not replace them.
Hiçbir yere. Ürün kendi sunucunuzda çalışır ve kayıtlarını kendi veritabanınızda tutar. Bulut bağımlılığı yoktur, üretim veriniz kurum dışına çıkmaz.Nowhere. The product runs on your own servers and keeps its records in your own database. There is no cloud dependency and your production data does not leave the organisation.
Şema, ürünle gelen numaralı betiklerle kurulur. Banka ve benzeri kurumlar için doğrulama modu vardır: betikleri veritabanı yöneticiniz kendi süreçlerinden geçirerek uygular ve uygulamanın hesabına şema değiştirme yetkisi verilmez.The schema is installed from numbered scripts shipped with the product. There is a validation mode for banks and similar institutions: your database administrator applies the scripts through their own process and the application account is never granted schema modification rights.
Kurumsal dizin ile giriş desteklenir, ikinci faktör açılabilir. Yetki sekiz rol seviyesi ve ekran bazlı izinlerle yönetilir. Yetki kontrolü ekranda değil sunucuda uygulanır.Sign in through your corporate directory is supported and a second factor can be enabled. Authorisation is managed through eight role levels and screen level permissions, and it is enforced on the server rather than in the interface.
Üretim verisine erişim talebe bağlanır, hassas kolonlar maskelenir ve maskesiz erişim gerekçesiyle kayıt altına alınır. Kullanıcı parolaları ve sunucu parolaları şifreli saklanır, denetim izi imzalanır. Uyumluluk dokümanı indirilebilir.Access to production data is tied to a request, sensitive columns are masked, and unmasked access is recorded with its justification. User and server passwords are stored encrypted and the audit trail is signed. A compliance document is available to download.
Bir talebin tüm yaşam döngüsü tek bir dosya olarak dışa aktarılır: kim istedi, o gün hangi kural seti yürürlükteydi, zaman çizelgesi, betiğin parmak izi, risk gerekçesi, maskeleme kararı ve doğrulanmış denetim kayıtları.
A request's whole lifecycle exports as a single file: who asked, which rule set was in force that day, the timeline, the script fingerprint, the risk rationale, the masking decision and the verified audit records.
Dosyanın kendi mührü vardır ve mühür denetim kaydına yazılır. Dosyanın üretimden sonra değişmediği bu mühürle kontrol edilir.
The file carries its own seal, and the seal is written into the audit record. That seal is how you check the file has not changed since it was produced.
İstisnalar gizlenmez. Talebi açan kişi kendi talebini çalıştırdıysa dosya bunu istisna olarak yazar. Yönetişimin ölçüsü ihlalin hiç olmaması değil, olduğunda görünmesidir.
Exceptions are not hidden. If the requester executed their own request, the file records it as an exception. Governance is not measured by the absence of violations but by whether they surface.
Aşağıdaki dosyalar ürünün gerçek çıktısıdır, tanıtım için hazırlanmış örnek değildir. Kayıt olmadan, e-posta vermeden indirip inceleyebilirsiniz. Denetim veya uyum tarafındaysanız kararınızı bir sunumdan değil, bu dosyadan verin.The files below are real product output, not mock-ups made for a brochure. Download and inspect them without signing up or leaving an email. If you sit on the audit or compliance side, judge us on this file rather than on a slide deck.
Tek bir talebin tüm yaşam döngüsü: talep, o günkü kural seti, zaman çizelgesi, betiğin parmak izi, risk gerekçesi, onaylar ve denetim kayıtları.One request's whole lifecycle: the request, the rule set of that day, the timeline, the script fingerprint, the risk rationale, the approvals and the audit records.
Dossier.pdf indirinDownload Dossier.pdfAynı dosyanın veri hali ve paket özeti. Mühür denetim izine yazılır; dosya sonradan ürüne verildiğinde özet yeniden hesaplanır ve karşılaştırılır.The same file as data, plus the package digest. The seal is written into the audit trail; hand the file back to the product later and the digest is recomputed and compared.
Dossier.json · · Manifest.jsonKişisel veri, saklama, maskeleme ve denetim izi konularında ürünün ne yaptığı ve neyi yapmadığı. Hukuk ve uyum biriminin soracağı sorular için.What the product does and does not do about personal data, retention, masking and the audit trail. Written for the questions your legal and compliance team will ask.
Uyumluluk_KVKK_TR.pdf indirin Download Compliance_KVKK_EN.pdfBileşenler, ağ topolojisi, veri akışı ve hangi hesabın neye eriştiği. Güvenlik incelemesine girmeden önce okunacak belge.Components, network topology, data flow and which account reaches what. The document to read before a security review starts.
SistemMimarisi_TR.pdf indirin Download SystemArchitecture_EN.pdfVeritabanı operasyonlarının ne kadar kontrollü olduğunu ve geçmişte ne olduğunu tek yerden görürsünüz.You see from one place how controlled database operations are and what happened in the past.
CISO, ComplianceÜretim verisine kimin, hangi gerekçeyle eriştiği ve hangi kolonun maskesiz gittiği kayıtta durur.Who reached production data, for what stated reason, and which column went out unmasked, all stay on record.
Veritabanı ekibiDatabase teamTalep, onay ve çalıştırma tek akışta ilerler. Geri alma betiği ve izole denemeyi ürün üretir.Request, approval and execution move in one flow. The rollback script and the sandbox trial come from the product.
CTO, DevOps ManagerVeritabanı işleri kontrollü bir teslim sürecinin içine girer, hattınız yerinde kalır.Database work joins a controlled delivery process while your pipeline stays where it is.
İç DenetimInternal AuditKim ne yaptı, neden yaptı, kim onayladı ve ne çalıştırıldı sorularının kanıtı tek dosyada.Who did what, why, who approved it and what ran: the evidence sits in one file.
Change ManagerOnay kuralı yazılı hale gelir ve talebin o günkü kural seti sonradan da okunabilir.The approval rule becomes written, and the rule set of that day stays readable later.
Infrastructure ManagerHangi sunucuda ne çalıştığı, kimin yetkisi olduğu ve bekleyen işin nerede durduğu görünür olur.What ran on which server, who holds which permission and where pending work stands all become visible.
Hattınız kalır. Biletiniz kalır. Kaydınız kalır. Yönetişim eklenir.Your pipeline stays. Your ticket stays. Your log stays. Governance is added.
Kurumların çoğu yeni bir araç almak istemiyor. Haklılar, zaten yeterince araç var.
Most enterprises do not want another tool. They are right. There are already enough tools.
Bu ürün var olanların üstüne sorumluluk koyar. Hattınız çalışmaya devam eder, değişiklik biletiniz yerinde kalır, log platformunuz aynı kalır. Değişen tek şey şudur: bunların hepsi artık tek bir karar ve kanıt modeline bağlanır.
This product places accountability above the ones you have. Your pipeline keeps running, your change ticket stays where it is, your log platform does not move. One thing changes: all of them now report into a single decision and evidence model.
Ne yapmadığını da söyleyelim: betiğinizi yazmaz, testinizi koşmaz, biletinizi kapatmaz. Bir tek şey yapar ve onu hiçbir aracınız yapmıyor: üretime giden işin kararını, kuralını ve kanıtını aynı kayıtta tutar.
It is also worth saying what it does not do. It does not write your scripts, it does not run your tests and it does not close your ticket. It does one thing, and none of your tools is doing it: it keeps the decision, the rule and the evidence of work bound for production on the same record.
Yeni bir araç eklemiyorsunuz. Sahip olduklarınızın üstüne tek bir karar ve kanıt modeli koyuyorsunuz.You are not adding another tool. You are putting one decision and evidence model on top of what you already run.
İlk görüşmelerde en sık gelen altı soru. Uzun hali sık sorulan sorular sayfasında.The six questions that come up most in a first conversation. The longer answers are on the frequently asked questions page.
Üretim veritabanına dokunan işin, gerçekleşmeden önce yazılı bir kurala göre değerlendirilmesi, yetkili bir kişi tarafından onaylanması ve sonradan kanıtlanabilmesidir. İki alanı birden kapsar: veritabanı değişikliği ve üretim verisine erişim. Değişiklik yönetiminden farkı, işin nasıl taşınacağını değil, geçmesine izin verilip verilmeyeceğini düzenlemesidir.It is the practice of assessing work that touches a production database against a written rule before it happens, having an authorised person approve it, and being able to prove it afterwards. It covers two areas at once: database change and production data access. It differs from change management in that it governs whether the work is allowed through rather than how it is carried.
Bir betiği gerçek dilbilgisiyle ayrıştırır, kural kataloğuna göre bulgularını çıkarır ve bir risk bandı belirler. Politikanın gerektirdiği onaylar tamamlanmadan çalıştırma açılmaz. Çalıştırma anında metnin özeti alınıp denetim kaydına mühürlenir, sonuç ve etkilenen satır sayısı kaydedilir. Nesne tanımı değişiklikleri için geri alma betiği önceden hazırlanır. Üretimden veri çekme talepleri de aynı döngüden geçer: hassas kolonlar maskelenir, sonuç şifreli paketle teslim edilir.It parses a script with a real grammar, produces findings against a rule catalog and sets a risk band. Execution does not open until the approvals the policy requires are complete. At execution the digest of the text is sealed into the audit record, and the outcome and affected row count are recorded. For object definition changes a rollback script is prepared in advance. Requests to extract production data go through the same loop: sensitive columns are masked and the result is delivered as an encrypted package.
Hayır. Bilet sistemi ne istendiğini, dağıtım hattı ne taşındığını, izleme aracı ne çalıştığını bilir. Hiçbiri çalışan metnin onaylanan metin olduğunu gösteremez, çünkü bu bilgi hiçbirinin görev tanımında yoktur. SQL Change Guard o bağı kurar ve bilet numarasıyla mevcut sisteminize bağlanır. Mevcut araçlarla ilişkisi.No. A ticketing system knows what was asked for, a pipeline knows what it carried, a monitor knows what ran. None of them can show that the text that ran is the text that was approved, because that is outside all of their remits. SQL Change Guard makes that link and connects to your existing system by ticket number. How it relates to your current tools.
Yönetilen hedef sistem olarak SQL Server, PostgreSQL ve Oracle. Her biri kendi dilbilgisiyle ayrıştırılır; ortak bir sözdizimi varsayımı yapılmaz. Ürünün kendi kayıtları bugün SQL Server üzerinde tutulur.As managed targets, SQL Server, PostgreSQL and Oracle. Each is parsed with its own grammar; no shared syntax is assumed. The product keeps its own records on SQL Server today.
Kurumun kendi ağında çalışır; bulut hizmeti değildir. Betikleriniz ve sorgu sonuçlarınız hiçbir dış servise gönderilmez, ürünün kayıtları da sizin sunucunuzda durur. Şifreleme anahtarları sizin yapılandırmanızdadır; üründe gömülü anahtar yoktur. Güvenlik mimarisi.It runs inside your own network; it is not a cloud service. Your scripts and query results are never sent to any external service, and the product keeps its records on your server. Encryption keys live in your configuration; there is no key embedded in the product. Security architecture.
Yavaşlatan şey kontrol değil, her değişikliğe aynı ağırlıkta kontrol uygulamaktır. Onay derinliği risk bandına göre belirlenir: düşük bant tek onayla geçer, yüksek bant çok kişili onay ister. Ölçülmesi gereken sayı onay adımı sayısı değil, talebin açılışından çalıştırılmasına kadar geçen süredir.What slows things down is not control, it is applying the same weight of control to every change. Approval depth follows the risk band: a low band passes with one approval, a high band requires several. The number to measure is not how many approval steps exist but how long a request takes from opening to execution.
Altı soru. Beş dakika. Satış görüşmesi değil.Six questions. Five minutes. Not a sales call.
Bu sorulardan üçüne "evet" diyemiyorsanız sorun aracınızda değil. Kurumda o katman yok.If you cannot say yes to three of these, the problem is not your tooling. The layer is missing.