{"id":1381,"date":"2026-09-21T09:01:06","date_gmt":"2026-09-21T05:01:06","guid":{"rendered":"https:\/\/www.buildingtheitguy.com\/?p=1381"},"modified":"2026-09-21T09:01:07","modified_gmt":"2026-09-21T05:01:07","slug":"change-management-the-it-process-everyone-ignores-until-something-breaks","status":"publish","type":"post","link":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/","title":{"rendered":"Change Management: The IT Process Everyone Ignores Until Something Breaks"},"content":{"rendered":"\n<style>\n.itcm{--text:#252525;--muted:#666;--line:#e4e4e1;--soft:#f7f7f5;--blue:#176fc1;max-width:780px;margin:auto;color:var(--text);font:18px\/1.72 system-ui,-apple-system,\"Segoe UI\",Roboto,Arial,sans-serif}.itcm *{box-sizing:border-box}.itcm .hero{padding:clamp(24px,5vw,44px);border:1px solid var(--line);border-radius:14px;background:linear-gradient(145deg,#edf6fd,#fff 70%)}.itcm .kicker{margin:0 0 8px;color:var(--blue);font-size:13px;font-weight:800;letter-spacing:.08em;text-transform:uppercase}.itcm h1{margin:0 0 16px;font-size:clamp(34px,6vw,54px);line-height:1.06;letter-spacing:-.04em}.itcm .lead{margin:0;color:var(--muted);font-size:20px;line-height:1.55}.itcm h2{margin:52px 0 14px;font-size:clamp(28px,4vw,36px);line-height:1.2;letter-spacing:-.02em}.itcm h3{margin:38px 0 10px;font-size:24px;line-height:1.3}.itcm p{margin:0 0 20px}.itcm ul,.itcm ol{margin:0 0 24px;padding-left:25px}.itcm li{margin:8px 0}.itcm a{color:var(--blue)}.itcm .callout{margin:28px 0;padding:16px 18px;border-left:4px solid var(--blue);border-radius:0 9px 9px 0;background:#edf6fd}.itcm .table-wrap{width:100%;margin:28px 0;overflow-x:auto}.itcm table{width:100%;min-width:680px;border-collapse:collapse;font-size:15px;line-height:1.45}.itcm th,.itcm td{padding:12px;border:1px solid var(--line);text-align:left;vertical-align:top}.itcm th{background:var(--soft)}.itcm pre{margin:26px 0;padding:18px;border:1px solid var(--line);border-radius:10px;background:var(--soft);overflow:auto;font:14px\/1.65 ui-monospace,SFMono-Regular,Menlo,Consolas,monospace}.itcm .cta{margin:48px 0;padding:24px;border:1px solid var(--line);border-radius:12px;background:var(--soft)}.itcm .btn{display:inline-block;padding:11px 17px;border-radius:8px;background:var(--blue);color:#fff;text-decoration:none;font-weight:700}.itcm .faq{padding:18px 0;border-bottom:1px solid var(--line)}.itcm .faq h3{margin:0 0 7px;font-size:19px}.itcm .faq p{margin:0;color:var(--muted)}@media(max-width:700px){.itcm{font-size:17px;line-height:1.68}.itcm h2{margin-top:42px}.itcm .hero{border-radius:10px}}\n<\/style>\n\n<article class=\"itcm\">\n<header class=\"hero\">\n<p class=\"kicker\">IT Service Management \u00b7 ITIL 4<\/p>\n<h1>Change Management: The IT Process Everyone Ignores Until Something Breaks<\/h1>\n<p class=\"lead\">Most IT departments already own ServiceNow, Jira Service Management or ManageEngine ServiceDesk Plus. The problem is not the missing tool. It is that the change module is switched on and the process still is not real.<\/p>\n<\/header>\n<p>A job advert landed in my feed this week, and it stopped me mid-scroll. A global engineering and development consultancy more than 20,000 people across over 50 countries was hiring in Dubai for an <strong>IT Specialist, Change Management<\/strong>. Permanent. Full time. Reporting to the IT Service Delivery Manager.<\/p>\n<p>Not infrastructure. Not security. Not cloud. One person, one process: change.<\/p>\n<p>The role owned the complete change lifecycle on top of a real ITSM platform: chairing the Change Advisory Board, maintaining the forward schedule of change, assessing technical and business risk, supporting security and compliance, keeping configuration records accurate, aligning change with release and deployment, defining ServiceNow KPIs, training users, and evaluating automation and GenAI.<\/p>\n<p>That is not a paperwork job. It is a governance and risk role with a technical spine and an organisation of that size decided it deserved dedicated, permanent headcount <strong>even though they already had the tool<\/strong>.<\/p>\n<p>Compare that with most IT departments I walk into. ServiceNow, Jira Service Management or ManageEngine ServiceDesk Plus is already licensed. The Change module is switched on. And change management is still the form completed on Friday for work that shipped on Tuesday. It is the meeting people join on mute. It is the first control dropped when a deadline gets tight, and the first evidence an auditor requests.<\/p>\n<p>This post is for that department. You already own the platform. Here is how to make change management actually work inside it.<\/p>\n<div class=\"callout\"><strong>The platform is not the process.<\/strong> ServiceNow, Jira and ServiceDesk Plus all ship a workflow engine and a configuration screen. They then ask you the same questions: which changes are pre-approved, what makes something high risk, who holds approval, what CAB reviews, when nobody may deploy, and which numbers you report. Answer those badly and you get an expensive tool that produces retroactively closed records.<\/div>\n<h2>First, the thing almost everyone gets wrong<\/h2>\n<p>Two different disciplines share the name \u201cchange management.\u201d<\/p>\n<p><strong>Organisational change management<\/strong> is about people: adoption, communication, resistance, and training. It is what you do when moving thousands of users to a new platform.<\/p>\n<p><strong>IT change management<\/strong>\u2014called <em>change enablement<\/em> in ITIL 4\u2014is about controlling technical changes to live services. Examples include:<\/p>\n<ul><li>A firewall rule or DNS record<\/li><li>A patch, driver, or firmware update<\/li><li>A SaaS administration setting<\/li><li>A database schema migration<\/li><li>A certificate renewal<\/li><li>A VM resize during business hours<\/li><\/ul>\n<p>A large share of unplanned downtime is self-inflicted. In many post-incident reviews, the trigger is a change nobody properly assessed, scheduled, or communicated\u2014often a change that never appeared in the tool at all, or appeared after it had already gone in.<\/p>\n<h2>Why it fails even when you have the tool<\/h2>\n<p>It is worth being honest about this, because \u201cour leadership does not care about process\u201d is usually not the real reason.<\/p>\n<p><strong>When it works, it is invisible.<\/strong> A quarter with no self-inflicted outages creates no dramatic story. Change management is insurance, and nobody thanks insurance.<\/p>\n<p><strong>The first configuration is often bureaucracy.<\/strong> Someone turns on every field the vendor ships, then books a one-hour CAB where the same four people rubber-stamp work they do not understand. Engineers route around it. Leadership concludes\u2014correctly, given the evidence\u2014that the module is a tax.<\/p>\n<p><strong>Incidents are loud; change is quiet.<\/strong> Outages receive tooling and executive attention. Prevention is a workflow nobody configured with care.<\/p>\n<p><strong>The licence is treated as the finish line.<\/strong> Buying ServiceNow, Jira or ServiceDesk Plus feels like the decision. It is only the purchase. Until you define standard changes, risk, approval authority and a real CAB, you have a ticket form with a different label.<\/p>\n<p>The cost appears elsewhere: repeat outages, audit findings, blame, and emergency change freezes that reveal the organisation does not trust its own controls.<\/p>\n<h2>The five things your platform must actually do<\/h2>\n<p>Strip away the product names. Any working change process does exactly five things. Your ITSM tool is only useful if it does them:<\/p>\n<ol><li><strong>Know what is changing before it changes.<\/strong> A record exists in the tool before hands go on keyboard.<\/li><li><strong>Match scrutiny to risk.<\/strong> A password reset and a core switch upgrade do not travel the same workflow.<\/li><li><strong>Make someone accountable for approval.<\/strong> Named authority in the approval policy, not a committee sharing the blame.<\/li><li><strong>Make the schedule visible.<\/strong> The change calendar is published, not a private list on the change manager\u2019s laptop.<\/li><li><strong>Learn from what went wrong.<\/strong> Failed and emergency changes produce an action, not just a closed ticket.<\/li><\/ol>\n<p>If your process does these five things, it is real. Which logo sits on the login page is implementation detail.<\/p>\n<h2>Where each decision lives in your tool<\/h2>\n<p>Feature names move between versions and editions, and change management is not always in the edition you bought. Check what you actually own. Then map the decisions to the screens you already have:<\/p>\n<div class=\"table-wrap\"><table><thead><tr><th>What you decide<\/th><th>ServiceNow<\/th><th>Jira Service Management<\/th><th>ManageEngine ServiceDesk Plus<\/th><\/tr><\/thead><tbody><tr><td>Standard change list<\/td><td>Change models and the Standard Change Catalog<\/td><td>Change types with pre-approved automation rules<\/td><td>Change templates<\/td><\/tr><tr><td>Risk scoring<\/td><td>Risk assessment questionnaire and risk conditions<\/td><td>Risk fields driven by automation rules<\/td><td>Risk and impact in the change workflow<\/td><\/tr><tr><td>Who approves what<\/td><td>Approval policies<\/td><td>Approvers per change type<\/td><td>Approver roles and CAB configuration<\/td><\/tr><tr><td>Schedule and blackouts<\/td><td>Change calendar, maintenance and blackout windows<\/td><td>Change calendar<\/td><td>Change calendar and downtime scheduling<\/td><\/tr><tr><td>Review after the fact<\/td><td>Closure and PIR fields on the change record<\/td><td>A review step you configure at closure<\/td><td>The Review stage of the change lifecycle<\/td><\/tr><tr><td>Reporting<\/td><td>Platform Analytics<\/td><td>Dashboards and reports<\/td><td>Change reports and dashboards<\/td><\/tr><\/tbody><\/table><\/div>\n<p>The rest of this post is what you type into those screens.<\/p>\n<h2>Configure it this week<\/h2>\n<p>Do not start by adding fields. Start by deciding the process, then configure the minimum that enforces it.<\/p>\n<h3>Step 1: Define three change types in the tool<\/h3>\n<p>Do not invent a taxonomy. Three is enough, and three is what ITIL collapses into anyway.<\/p>\n<div class=\"table-wrap\"><table><thead><tr><th>Type<\/th><th>Definition<\/th><th>Approval<\/th><th>Examples<\/th><th>Configure as<\/th><\/tr><\/thead><tbody><tr><td><strong>Standard<\/strong><\/td><td>Low-risk, repeatable work with documented steps and a known outcome.<\/td><td>Template is pre-approved; log each execution.<\/td><td>User onboarding, routine non-production patching, certificate renewal by runbook.<\/td><td>ServiceNow change model \/ catalog item; Jira pre-approved change type; SDP change template<\/td><\/tr><tr><td><strong>Normal<\/strong><\/td><td>Everything else; requires assessment and a planned window.<\/td><td>Change manager, or CAB when high risk.<\/td><td>Firewall change, production patching, network configuration, ERP release.<\/td><td>Default Normal workflow with risk-based CAB<\/td><\/tr><tr><td><strong>Emergency<\/strong><\/td><td>Work required to fix or prevent a major incident immediately.<\/td><td>Two-person approval, documented within 24 hours, reviewed at next CAB.<\/td><td>Emergency security patch or failed-over service repair.<\/td><td>Emergency workflow with shortened lead time and mandatory PIR<\/td><\/tr><\/tbody><\/table><\/div>\n<p>Most change volume should eventually become <strong>Standard<\/strong>. Standard templates are how teams move quickly without guessing, and how you stop your approval queue becoming the reason people bypass the tool.<\/p>\n<p>If every record in your instance is type Normal, you have not configured change management. You have configured a slower incident ticket.<\/p>\n<h3>Step 2: Keep the change record to one screen<\/h3>\n<p>If the form does not fit on one screen, people will lie in it to get through it. Hide vendor fields you do not use. Eleven are enough:<\/p>\n<pre>CHANGE RECORD\n1.  Change ID             (auto from the platform)\n2.  Title                 Upgrade firmware on core switch\n3.  Requested by          Name and team\n4.  Implementer           Person performing the work\n5.  Type                  Standard \/ Normal \/ Emergency\n6.  Systems affected      CIs and dependent services\n7.  Business impact       Who notices and for how long\n8.  Risk score            Impact \u00d7 likelihood\n9.  Implementation window Start and end time\n10. Validation plan       How success will be verified\n11. Rollback plan         How to undo it and duration<\/pre>\n<div class=\"callout\"><strong>No rollback plan, no approval.<\/strong> \u201cRestore from backup\u201d is not enough. Require a real method and estimated duration. Make the rollback field mandatory on Normal and Emergency. Half the bad changes die at this question, before they reach production.<\/div>\n<p>Map systems affected to actual configuration items. Impact analysis is only as good as the CMDB behind it. You do not need a perfect CMDB\u2014you need accurate dependencies for the systems that would hurt most, kept current when changes close.<\/p>\n<h3>Step 3: Score risk in the workflow, not in a side spreadsheet<\/h3>\n<p>Ask five questions, then let the platform calculate or classify:<\/p>\n<p>Does it touch production or a shared system? Will users notice if it fails? Can it be reversed within 15 minutes? Has this exact change succeeded here before? Is a maintenance window available?<\/p>\n<div class=\"table-wrap\"><table><thead><tr><th>Business impact<\/th><th>Low likelihood<\/th><th>Medium likelihood<\/th><th>High likelihood<\/th><\/tr><\/thead><tbody><tr><td>High<\/td><td>Medium<\/td><td>High<\/td><td>High<\/td><\/tr><tr><td>Medium<\/td><td>Low<\/td><td>Medium<\/td><td>High<\/td><\/tr><tr><td>Low<\/td><td>Low<\/td><td>Low<\/td><td>Medium<\/td><\/tr><\/tbody><\/table><\/div>\n<p>Connect the score to authority so nobody has to ask who approves what:<\/p>\n<div class=\"table-wrap\"><table><thead><tr><th>Risk<\/th><th>Approved by<\/th><th>Lead time<\/th><th>In the tool<\/th><\/tr><\/thead><tbody><tr><td>Low<\/td><td>Team lead, or pre-approved as a standard template<\/td><td>Same day<\/td><td>Auto-approve, or one named approver<\/td><\/tr><tr><td>Medium<\/td><td>Named change manager<\/td><td>2 working days<\/td><td>Approval policy, CAB notified<\/td><\/tr><tr><td>High<\/td><td>CAB plus the business owner of the affected service<\/td><td>5 working days<\/td><td>CAB agenda item, service owner required<\/td><\/tr><\/tbody><\/table><\/div>\n<p>Put this matrix in the risk questionnaire or in a knowledge article linked from the form. If it lives only in a PDF on SharePoint, it does not exist.<\/p>\n<h3>Step 4: Run a 15-minute CAB off the tool, not a status meeting<\/h3>\n<p>The Change Advisory Board has a terrible reputation because it is almost always run as a readout of the queue. It is not. It is a short risk conversation about a pre-read that already exists as change records.<\/p>\n<pre>CAB AGENDA \u2014 weekly, same time\n00:00\u201305:00  Last week: what shipped, failed, or caused an incident\n05:00\u201312:00  This week: risks, conflicts, dependencies, decisions\n12:00\u201315:00  Emergency changes, freezes, and blackout periods<\/pre>\n<ul><li><strong>Pre-read is mandatory.<\/strong> Incomplete records move to the next meeting. The platform already shows you which fields are empty\u2014use that, do not rediscover it verbally.<\/li><li><strong>CAB does not design the change.<\/strong> Reject an unfinished plan. Do not workshop it in the meeting.<\/li><li><strong>Invite the right people.<\/strong> Whoever understands the dependency, plus the service owner. Seniority is not a substitute for blast-radius knowledge.<\/li><li><strong>Record decisions in the record.<\/strong> Approve, approve with conditions, or reject, with the reason. That is your audit trail. Do not keep a parallel CAB minutes document unless your auditor specifically requires it.<\/li><\/ul>\n<p>ServiceNow has CAB Workbench. ServiceDesk Plus has CAB configuration. Jira can drive approvals asynchronously so the meeting only covers what actually needs a conversation. Use those. A ten-person board reviewing password resets is not governance.<\/p>\n<h3>Step 5: Publish the forward schedule from the change calendar<\/h3>\n<p>Every approved change already has a window in the record. Put the platform\u2019s change calendar in front of the people who get hurt by surprises: service desk, finance, operations, the application owners.<\/p>\n<p>Add blackout periods\u2014month end, financial close, payroll, peak trading, major client events\u2014in the same calendar. A freeze published in advance is governance. A freeze announced by email on the day is panic.<\/p>\n<p>This is also how you discover that an ERP patch window lands on the second day of finance close, while there is still time to move it.<\/p>\n<h3>Step 6: Close the loop in the Review stage<\/h3>\n<p>Review every failed change, every rolled-back change, every emergency change, and every high-risk change. Four questions:<\/p>\n<ol><li>Did it achieve the intended result?<\/li><li>Did it remain inside the approved window?<\/li><li>Did it cause an incident or require rollback?<\/li><li>Would a standard template, better testing, or automation prevent recurrence?<\/li><\/ol>\n<p>The review must create an action in the tool: a new standard template, a runbook update, a monitoring gap closed, a CMDB correction, or an automation request. If reviews produce no tickets, you are collecting closure comments, not running a process.<\/p>\n<p>In ServiceDesk Plus this is the Review stage. In ServiceNow it is post-implementation fields and a follow-up task. In Jira it is a review status you add at the end of the workflow. Configure it so a High-risk or Failed change cannot close without it.<\/p>\n<h2>Wire it into how you actually ship<\/h2>\n<p>This is where modern change management either becomes an enabler or gets abandoned, and it is why that job advert specifically mentioned release, deployment and CI\/CD.<\/p>\n<p>If engineers copy information out of a pipeline and paste it into ServiceNow or Jira, one of two things happens: they stop deploying frequently, or they write fiction in the form. Neither is a control.<\/p>\n<p>The fix is to make the pipeline the source of the record:<\/p>\n<ul><li>Define a <strong>standard change model per pipeline<\/strong>, not per deployment.<\/li><li>Let the pipeline <strong>create the change record automatically<\/strong> from the commit, the ticket and the build.<\/li><li><strong>Auto-approve when gates pass:<\/strong> tests green, security scan clean, peer review approved, deploying inside an allowed window.<\/li><li>Attach the artefact version and the rollback method (previous image, previous migration, feature flag off) automatically.<\/li><li><strong>Auto-close on success<\/strong>, and involve a human only when a gate fails or the deployment lands outside policy.<\/li><\/ul>\n<p>Done properly, deployment frequency rises while audit evidence improves. That is the argument that wins with leadership, not \u201cITIL says so.\u201d<\/p>\n<p>ServiceNow supports this through change models, IntegrationHub and DevOps Change Velocity. Jira does it through automation rules and development-tool connections. ServiceDesk Plus does it through the change API and request workflows. Pick the integration your edition actually includes, then start with one pipeline, not a grand design.<\/p>\n<h2>The five numbers worth reporting from the platform<\/h2>\n<p>Do not invent a side spreadsheet for KPIs. Pull them from Platform Analytics, Jira dashboards or ServiceDesk Plus change reports.<\/p>\n<div class=\"table-wrap\"><table><thead><tr><th>Metric<\/th><th>What it tells you<\/th><th>Starting target<\/th><\/tr><\/thead><tbody><tr><td>Change success rate<\/td><td>Quality of risk assessment<\/td><td>Above 95%<\/td><\/tr><tr><td>Standard changes as a share of all changes<\/td><td>Maturity and removed friction<\/td><td>Above 60%<\/td><\/tr><tr><td>Completed inside the planned window<\/td><td>Planning quality<\/td><td>Above 90%<\/td><\/tr><tr><td>Automated versus manual changes<\/td><td>Consistency and repeatability<\/td><td>Trending upward<\/td><\/tr><tr><td>Emergency-change percentage<\/td><td>Whether emergency is used to bypass control<\/td><td>Below 5%<\/td><\/tr><\/tbody><\/table><\/div>\n<p>Two warnings. Do not report on approval counts or meeting attendance; they measure ceremony. And do not chase a 100% success rate\u2014it does not mean you are excellent, it means either you have stopped doing anything meaningful, or changes are happening off the books. Add one qualitative check twice a year: ask engineers and business stakeholders whether the process helped them. A process with a 99% success rate and no internal credibility will be bypassed the moment you are on leave.<\/p>\n<h2>Anti-patterns the tool makes easy<\/h2>\n<ul><li><strong>Every change logged as Normal<\/strong> because nobody created standard templates.<\/li><li><strong>CAB used as a design workshop.<\/strong> If the meeting is fixing the plan, the plan was not ready.<\/li><li><strong>Approval by the most senior person<\/strong> instead of the person who understands the blast radius.<\/li><li><strong>Routine retroactive logging.<\/strong> Closing records after implementation is documentation, not control. Report \u201ccreated after implementation\u201d as its own metric if your platform can.<\/li><li><strong>A freeze used instead of risk assessment.<\/strong> Freezes are what you do when you cannot assess risk quickly.<\/li><li><strong>One risk level for everything.<\/strong> Treat every change as high risk and you create a queue, and a queue creates shadow changes.<\/li><li><strong>A parallel spreadsheet next to the ITSM tool.<\/strong> The moment you have two sources of truth, neither is trusted.<\/li><li><strong>Process guidance nobody can find.<\/strong> Link the matrix and the standard catalog from the change form. If it takes more than one click, it does not exist.<\/li><\/ul>\n<h2>Your first 30 days\u2014on the platform you already have<\/h2>\n<p>Resist the urge to redesign the entire workflow in week one. Use the records that already exist.<\/p>\n<ol><li><strong>Week 1\u2014see it.<\/strong> Export last month\u2019s change records. Count Standard versus Normal versus Emergency. Count how many were created after the implementation window. Count how many caused an incident. You are buying honesty, not adding controls.<\/li><li><strong>Week 2\u2014sort it.<\/strong> Identify the ten most frequent, lowest-risk, repeated changes. Turn them into standard templates in ServiceNow, Jira or ServiceDesk Plus. You have just removed most of your future approval load.<\/li><li><strong>Week 3\u2014govern it.<\/strong> Publish the risk matrix and who approves what, then configure those approval policies. Start a 15-minute CAB using the platform calendar as the agenda. Publish blackout windows.<\/li><li><strong>Week 4\u2014prove it.<\/strong> Put success rate and emergency ratio on a dashboard the service owner can see. Require a review on every failure. Pick the single most annoying manual change and automate the record creation from the pipeline or the runbook.<\/li><\/ol>\n<p>Then review quarterly: what is still bureaucratic, what is being bypassed, what should become a standard template, what should become code.<\/p>\n<section class=\"cta\"><h2 style=\"margin-top:0\">Skip the blank page<\/h2><p>The starter kit is not a replacement for ServiceNow, Jira or ServiceDesk Plus. It is the configuration input those platforms ask you for: a one-page record so you know which fields to keep, a 15-minute CAB agenda, a starter catalogue of eight standard changes, a risk and approval matrix, and a post-implementation review sheet. Throw the spreadsheet away. Use the rest to fill the screens.<\/p><a class=\"btn\" href=\"https:\/\/www.buildingtheitguy.com\/wp-content\/uploads\/2026\/09\/change-management-starter-kit-1.zip\">Download the change management starter kit<\/a><\/section>\n<h2>Why this matters to your IT career<\/h2>\n<p>Go back to that job advert. It asked for ITIL 4, ServiceNow administration, CMDB and dependency mapping, Platform Analytics, audit support, training, automation and GenAI evaluation. That is a specialism with a clear ladder, in demand at organisations large enough to have felt the pain of owning the tool and still getting hurt by change.<\/p>\n<p>You do not need a 20,000-person company to build this experience. You need one ServiceNow, Jira or ServiceDesk Plus instance, and the discipline to configure the next standard template instead of letting another Normal ticket through.<\/p>\n<p>Do that for a quarter and show a success rate and emergency ratio you can defend. You become the person who made deployments boring\u2014and boring deployments are worth far more than they sound.<\/p>\n<h2>Frequently asked questions<\/h2>\n<section class=\"faq\"><h3>Is change management the same as change enablement?<\/h3><p>Practically, yes. ITIL 4 renamed the practice to emphasise enabling safe change. Most organisations, tools and job adverts still use \u201cchange management.\u201d<\/p><\/section>\n<section class=\"faq\"><h3>We already have ServiceNow, Jira or ServiceDesk Plus. Do we still need this?<\/h3><p>Yes. The platform supplies the workflow. You still have to decide the standard change list, risk thresholds, approval authority, what CAB reviews, blackout periods and KPI targets. Those decisions are what you type into the configuration screens.<\/p><\/section>\n<section class=\"faq\"><h3>Does a small business need a CAB if the tool can auto-approve?<\/h3><p>It needs the function, not the furniture. Auto-approve Standard and Low-risk Normal. Two people reviewing a high-risk change for 15 minutes, with the decision recorded on the ticket, is enough.<\/p><\/section>\n<section class=\"faq\"><h3>What makes a change standard?<\/h3><p>It is repeatable, documented, low risk, and has a reliable record of success. Approve the template once in the catalog, then log each execution against it.<\/p><\/section>\n<section class=\"faq\"><h3>How do I prevent emergency-change abuse?<\/h3><p>Define it narrowly in the emergency workflow, require two approvers, document it within 24 hours, review every instance at the next CAB, and report the percentage from the platform. Visibility does most of the enforcement.<\/p><\/section>\n<section class=\"faq\"><h3>Will this slow down DevOps teams?<\/h3><p>Only if people retype what the pipeline already knows. Standard change models, automated record creation and gate-based approvals support faster deployment with stronger evidence than a manual form.<\/p><\/section>\n<section class=\"faq\"><h3>What if our edition does not include change management?<\/h3><p>Then check whether you can add the module, or whether you are on a service-desk edition that stops at incident and request. Do not fake a change process inside incident tickets. Either licence the workflow or keep a deliberately small, honest process until you can.<\/p><\/section>\n<p style=\"margin-top:40px;padding-top:24px;border-top:1px solid #e4e4e1;color:#666\">If you are configuring this in your own instance and want a second pair of eyes on your risk matrix or standard-change list, leave a comment or send me a message. I would rather help you skip the version of this that engineers learn to route around.<\/p>\n<\/article>\n","protected":false},"excerpt":{"rendered":"<p>IT Service Management \u00b7 ITIL 4 Change Management: The IT Process Everyone Ignores Until Something Breaks Most IT departments already own ServiceNow, Jira Service Management or ManageEngine ServiceDesk Plus. The problem is not the missing tool. It is that the change module is switched on and the process still is not real. A job advert [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1385,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[97],"tags":[172,185,186,181,187,182,100,184,183],"class_list":["post-1381","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it-operation","tag-buildingtheitguy","tag-cab","tag-change-enablement","tag-change-management","tag-it-service-management","tag-itil-4","tag-itsm","tag-jira","tag-servicenow"],"featured_image_src":"https:\/\/www.buildingtheitguy.com\/wp-content\/uploads\/2026\/09\/WP-featured-change-management-1200x630-1.png","author_info":{"display_name":"Mohamed Asath","author_link":"https:\/\/www.buildingtheitguy.com\/index.php\/author\/asathwebtieradmin\/"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Change Management: The IT Process Everyone Ignores Until Something Breaks - Building THE IT GUY<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Change Management: The IT Process Everyone Ignores Until Something Breaks - Building THE IT GUY\" \/>\n<meta property=\"og:description\" content=\"IT Service Management \u00b7 ITIL 4 Change Management: The IT Process Everyone Ignores Until Something Breaks Most IT departments already own ServiceNow, Jira Service Management or ManageEngine ServiceDesk Plus. The problem is not the missing tool. It is that the change module is switched on and the process still is not real. A job advert [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/\" \/>\n<meta property=\"og:site_name\" content=\"Building THE IT GUY\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-21T05:01:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2026-09-21T05:01:07+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.buildingtheitguy.com\/wp-content\/uploads\/2026\/09\/WP-featured-change-management-1200x630-1.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Mohamed Asath\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mohamed Asath\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"15 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/\"},\"author\":{\"name\":\"Mohamed Asath\",\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/#\\\/schema\\\/person\\\/cce03fcda4c40ccf57ab3844ca707561\"},\"headline\":\"Change Management: The IT Process Everyone Ignores Until Something Breaks\",\"datePublished\":\"2026-09-21T05:01:06+00:00\",\"dateModified\":\"2026-09-21T05:01:07+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/\"},\"wordCount\":3169,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/WP-featured-change-management-1200x630-1.png\",\"keywords\":[\"BuildingTHEITGUY\",\"CAB\",\"change enablement\",\"change management\",\"IT service management\",\"ITIL 4\",\"ITSM\",\"Jira\",\"ServiceNow\"],\"articleSection\":[\"IT Operation\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/\",\"url\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/\",\"name\":\"Change Management: The IT Process Everyone Ignores Until Something Breaks - Building THE IT GUY\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/WP-featured-change-management-1200x630-1.png\",\"datePublished\":\"2026-09-21T05:01:06+00:00\",\"dateModified\":\"2026-09-21T05:01:07+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/#\\\/schema\\\/person\\\/cce03fcda4c40ccf57ab3844ca707561\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/WP-featured-change-management-1200x630-1.png\",\"contentUrl\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/WP-featured-change-management-1200x630-1.png\",\"width\":1200,\"height\":630,\"caption\":\"ITIL 4 change management \u2014 process before tools.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/change-management-the-it-process-everyone-ignores-until-something-breaks\\\/it-operation\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Change Management: The IT Process Everyone Ignores Until Something Breaks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/#website\",\"url\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/\",\"name\":\"Building THE IT GUY\",\"description\":\"Making Everyone&#039;s Life Easier\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/#\\\/schema\\\/person\\\/cce03fcda4c40ccf57ab3844ca707561\",\"name\":\"Mohamed Asath\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ab17cc6285a5051affe4181f53011c89cc055de9416bcc44b3e2771be318d870?s=96&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ab17cc6285a5051affe4181f53011c89cc055de9416bcc44b3e2771be318d870?s=96&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/ab17cc6285a5051affe4181f53011c89cc055de9416bcc44b3e2771be318d870?s=96&r=g\",\"caption\":\"Mohamed Asath\"},\"description\":\"Turning IT Challenges into Opportunities\",\"sameAs\":[\"https:\\\/\\\/www.buildingtheitguy.com\"],\"url\":\"https:\\\/\\\/www.buildingtheitguy.com\\\/index.php\\\/author\\\/asathwebtieradmin\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Change Management: The IT Process Everyone Ignores Until Something Breaks - Building THE IT GUY","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/","og_locale":"en_US","og_type":"article","og_title":"Change Management: The IT Process Everyone Ignores Until Something Breaks - Building THE IT GUY","og_description":"IT Service Management \u00b7 ITIL 4 Change Management: The IT Process Everyone Ignores Until Something Breaks Most IT departments already own ServiceNow, Jira Service Management or ManageEngine ServiceDesk Plus. The problem is not the missing tool. It is that the change module is switched on and the process still is not real. A job advert [&hellip;]","og_url":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/","og_site_name":"Building THE IT GUY","article_published_time":"2026-09-21T05:01:06+00:00","article_modified_time":"2026-09-21T05:01:07+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.buildingtheitguy.com\/wp-content\/uploads\/2026\/09\/WP-featured-change-management-1200x630-1.png","type":"image\/png"}],"author":"Mohamed Asath","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Mohamed Asath","Est. reading time":"15 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/#article","isPartOf":{"@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/"},"author":{"name":"Mohamed Asath","@id":"https:\/\/www.buildingtheitguy.com\/#\/schema\/person\/cce03fcda4c40ccf57ab3844ca707561"},"headline":"Change Management: The IT Process Everyone Ignores Until Something Breaks","datePublished":"2026-09-21T05:01:06+00:00","dateModified":"2026-09-21T05:01:07+00:00","mainEntityOfPage":{"@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/"},"wordCount":3169,"commentCount":0,"image":{"@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/#primaryimage"},"thumbnailUrl":"https:\/\/www.buildingtheitguy.com\/wp-content\/uploads\/2026\/09\/WP-featured-change-management-1200x630-1.png","keywords":["BuildingTHEITGUY","CAB","change enablement","change management","IT service management","ITIL 4","ITSM","Jira","ServiceNow"],"articleSection":["IT Operation"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/","url":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/","name":"Change Management: The IT Process Everyone Ignores Until Something Breaks - Building THE IT GUY","isPartOf":{"@id":"https:\/\/www.buildingtheitguy.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/#primaryimage"},"image":{"@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/#primaryimage"},"thumbnailUrl":"https:\/\/www.buildingtheitguy.com\/wp-content\/uploads\/2026\/09\/WP-featured-change-management-1200x630-1.png","datePublished":"2026-09-21T05:01:06+00:00","dateModified":"2026-09-21T05:01:07+00:00","author":{"@id":"https:\/\/www.buildingtheitguy.com\/#\/schema\/person\/cce03fcda4c40ccf57ab3844ca707561"},"breadcrumb":{"@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/#primaryimage","url":"https:\/\/www.buildingtheitguy.com\/wp-content\/uploads\/2026\/09\/WP-featured-change-management-1200x630-1.png","contentUrl":"https:\/\/www.buildingtheitguy.com\/wp-content\/uploads\/2026\/09\/WP-featured-change-management-1200x630-1.png","width":1200,"height":630,"caption":"ITIL 4 change management \u2014 process before tools."},{"@type":"BreadcrumbList","@id":"https:\/\/www.buildingtheitguy.com\/index.php\/change-management-the-it-process-everyone-ignores-until-something-breaks\/it-operation\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.buildingtheitguy.com\/"},{"@type":"ListItem","position":2,"name":"Change Management: The IT Process Everyone Ignores Until Something Breaks"}]},{"@type":"WebSite","@id":"https:\/\/www.buildingtheitguy.com\/#website","url":"https:\/\/www.buildingtheitguy.com\/","name":"Building THE IT GUY","description":"Making Everyone&#039;s Life Easier","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.buildingtheitguy.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.buildingtheitguy.com\/#\/schema\/person\/cce03fcda4c40ccf57ab3844ca707561","name":"Mohamed Asath","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/ab17cc6285a5051affe4181f53011c89cc055de9416bcc44b3e2771be318d870?s=96&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/ab17cc6285a5051affe4181f53011c89cc055de9416bcc44b3e2771be318d870?s=96&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ab17cc6285a5051affe4181f53011c89cc055de9416bcc44b3e2771be318d870?s=96&r=g","caption":"Mohamed Asath"},"description":"Turning IT Challenges into Opportunities","sameAs":["https:\/\/www.buildingtheitguy.com"],"url":"https:\/\/www.buildingtheitguy.com\/index.php\/author\/asathwebtieradmin\/"}]}},"_links":{"self":[{"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/posts\/1381","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/comments?post=1381"}],"version-history":[{"count":4,"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/posts\/1381\/revisions"}],"predecessor-version":[{"id":1388,"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/posts\/1381\/revisions\/1388"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/media\/1385"}],"wp:attachment":[{"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/media?parent=1381"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/categories?post=1381"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.buildingtheitguy.com\/index.php\/wp-json\/wp\/v2\/tags?post=1381"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}