Seven capabilities. One layer of engineering judgment over production change.
ChangeGuard watches every change to your Kubernetes fleet, correlates failures to the changes that caused them, and brings your team’s judgment into what ships next — with as much or as little autonomy as you grant it.
Change Intelligence
A continuously-updated record of every deployment, config, and GitOps change across your fleet — and, crucially, the link from each failing workload back to the exact change that shipped it, with the diff.
- Change timeline per cluster, from your CI and GitOps (ArgoCD / Flux)
- Failing workload → commit + diff that shipped it
- The substrate everything else reasons over

Incident investigation
Detect a failing workload, explain the root cause with cited evidence, propose a fix, and state how to verify it — automatically, the moment the incident is detected.
- Root cause with confidence and cited evidence
- Proposed fix (code patch or manifest change) and explicit verify criteria
- Append-only activity timeline on every incident

The judgment layer
A deterministic verdict you can trust — and the capabilities that turn it into the read a senior engineer would give.
CSC Score & pre-flight checks
A deterministic, explainable 0–100 deploy-readiness score, and an on-demand SHIP / HOLD / BLOCK verdict with reasons. Advisory — it never blocks your pipeline.
Current Understanding
The maintained, change-centric read of an incident — what a newcomer needs to know right now, not a log of everything that ever happened.
Engineering Advisor
The teammate that remembers every production change. The one or two things a senior engineer would raise before a change proceeds — led by what’s true right now, challengeable, and honest about what it can’t see. Read the full Advisor page →
Engineering Opinion & Reasoning
ChangeGuard’s owned position on an incident — belief, confidence, tradeoffs, and honest ✓/⚠ factors — with the reasoning shown, not hidden.
Institutional Engineering Memory
Engineering Experience: what similar past incidents and changes actually did — real counts, real outcomes — woven in only when it changes the decision.
Multiplayer Collaboration
A shared incident workspace so the whole team works from one current understanding instead of re-deriving it in five threads — with ChangeGuard as a participant, not a chatbot.
Verified Remediation (Self-Healing)
A closed loop — detect, diagnose, execute within policy, verify, roll back — governed entirely by autonomy levels you set. Off by default; it starts in Advise and never acts beyond the level you choose.
Observe
Watch and record. No recommendations surfaced to act on.
Advise default
Recommend fixes. Nothing executes.
Approve
Act only after a human approves each action.
Auto
Act automatically, but only inside an explicit execution policy: allowed namespaces, fix types, a confidence floor, and an hourly cap.
Every applied fix is verified against real workload health. If it fails verification, ChangeGuard performs exactly one audited rollback and hands the incident to a human. See the autonomy & safety docs →
Security & Trust
Posture scanning
CIS benchmarks (KubeBench), image CVEs (Grype), deprecated APIs (Pluto), SBOM (Syft), and runtime threat detection (Falco) — feeding the CSC Score.
Identity & access
RBAC analysis, over-privileged identity detection, and a privilege-escalation / attack-path graph.
Compliance mapping
Maps scan, RBAC, and SBOM evidence to framework controls (SOC 2, PCI, HIPAA, and more) and exports it as CSV/JSON. ChangeGuard helps you evidence controls — it is not a certification.
Try it on your own cluster
Everything above starts the moment the collector connects. Advisory by default.