06

Integrations

Keep work in place. Connect the meaning around it.

ChangeFlow reads a bounded customer-approved scope, normalizes important events, reconciles source state, and writes low-risk coordination work back where teams operate.

Systemsof record
ChangeFlow
Tasks+ decisions

Microsoft-first MVP

Six integrations complete one release-readiness loop.

The first integration set is narrow by design: enough to connect delivery, knowledge, identity, AI evidence, collaboration, and outcomes.

Integration architectureRead context in. Write accountable work back.
Enterprise systems
ADODeliverySPKnowledgeIDIdentityAIEvaluationBIOutcomeSNService
WebhookSyncReconcileCanonical eventssigned · versioned · idempotent
ChangeFlowChange
intelligence
core
Graph · policy · evidence
Controlled actions
TaskAzure DevOpsApproveTeamsDraftSharePointBriefLeaders
PreviewAuthorizeIdempotency keyWriteReconcile
SystemRolePurposeMode
Azure DevOpsDelivery

Scope, owners, dates, dependencies, work-item history

Read + write
SharePointKnowledge

Policies, SOPs, architecture, training, document versions

Read + drafts
Microsoft TeamsCollaboration

Briefs, notifications, scoped approvals, deep links

Interact
Microsoft EntraIdentity

Authentication, groups, owners, affected populations

Read
Foundry / Copilot StudioAI engineering

Agent versions, tools, evaluations, operational evidence

Read
Fabric / Power BIOutcomes

Baselines, adoption, operations, business measures

Read

The connector pattern

Fresh enough for action. Safe enough for trust.

Each connector follows the same contract so vendor behavior stays outside the core domain.

01

Discover

List approved projects, sites, groups, agents, and models without importing all of them.

02

Synchronize

Perform an initial bounded import, then process incremental events and scheduled reconciliation.

03

Normalize

Map source payloads to canonical entities, external references, and vendor-neutral events.

04

Act

Preview and execute approved write-back with authorization, idempotency, result, and deep link.

05

Observe

Expose authentication, subscription, rate limit, cursor, freshness, and failure health.

Engineering domain pack

Extend the same connector contract into platform and security evidence.

A domain pilot adds only the sources required by the selected release; reviewed references can stand in until repeated use justifies another connector.

Code + supply chain

Azure Repos or GitHub, artifact registry, SBOM, signing and pipeline attestations

Cloud + runtime

Azure Resource Graph, ARM, AKS, Kubernetes, infrastructure-as-code and policy state

Identity + secrets

Entra managed identities, role assignments, Key Vault secrets and certificates

Security

Defender for Cloud, Defender for DevOps, dependency, container and posture findings

Reliability

Azure Monitor, Application Insights, Log Analytics, SLOs, alerts and dashboards

Operations

ServiceNow or equivalent service ownership, incidents, runbooks and support evidence

Write-back safety

Every external action has an accountable trail.

  • 01Initiating user or approved automation
  • 02Human-readable action preview
  • 03Resolved target and permitted fields
  • 04Idempotency key to stop duplicate work
  • 05Request, result, external ID, and deep link
  • 06Correlation to release and obligation

Start with one real release

Make readiness visible before production makes gaps expensive.

See the MVP