RESOURCES · IT GOVERNANCE

Change management & the
four-eye review

In IT, a surprising share of serious outages aren't caused by hackers at all — they're caused by well-meaning changes that went wrong. And many security gaps start the same way: a misconfiguration no one double-checked. "Change management" and the "four-eye review" are the disciplines that stop that happening. Here's what they mean, why they matter, and how a good IT partner uses them to protect your business.

Applies to: Every business that relies on IT Read: ~5 min Level: Non-technical
Quick answer

Change management is a controlled way of making changes to your IT — every significant change is assessed, approved, planned with a way to undo it, then carefully implemented — instead of someone editing something live and hoping. The four-eye review (or "four-eyes principle") means at least two qualified people check a change before it goes ahead. Together, they prevent avoidable outages, mistakes and security gaps.

WHY CHANGES ARE RISKY

The biggest cause of downtime isn't hackers — it's change.

Ask any seasoned engineer what causes most outages and they'll tell you: a change that didn't go to plan. A single mistaken firewall rule, a wrong DNS edit, or a configuration pushed without testing can take email — or an entire network — offline in seconds. Do it in a rush, late on a Friday, with no second opinion and no way to undo it, and a five-minute job becomes a lost day. Change management exists to make sure that never happens to your business.

THE PROCESS

What change management actually involves.

It's not red tape — it's a simple, repeatable process that makes changes safe:

  1. Request & documentThe change is written down — what's changing, why, and what it affects — so nothing happens off-the-cuff or undocumented.
  2. Assess the risk & impactHow risky is it? What could it break? Who's affected, and when's the safest time to do it?
  3. Approve itThe right people sign off before anything is touched — including a second engineer for anything high-impact (the four-eye review below).
  4. Plan the change — and the way backEvery significant change gets a rollback plan: a tested way to undo it quickly if something goes wrong. It's the step rushed jobs skip.
  5. Schedule & communicateWhere needed, it's done outside business hours, and anyone affected is told in advance — no nasty surprises.
  6. Implement carefullyThe change is made methodically, following the plan, not improvised on the fly.
  7. Review & confirmWe check it worked as intended, confirm nothing else broke, and record the outcome.
THE FOUR-EYE REVIEW

Two sets of eyes, every time.

The four-eyes principle (you may also hear it called the two-person rule or dual control) is simple: no single person makes a significant change alone. A second qualified engineer reviews and approves it before it goes live. It's the same control a bank uses when two people must authorise a large payment — and it's powerful for three reasons:

WHERE IT APPLIES

The changes we never do single-handed.

High-impact changes get a mandatory second review before they're made — for example:

"WON'T THIS SLOW US DOWN?"

Careful doesn't mean slow.

It's a fair question — and the answer is no. Routine, low-risk changes like a password reset or adding a new user are streamlined and simply get done. The full assessment and second review are reserved for genuinely high-impact changes. And for real emergencies, there's a fast-tracked path so we can act immediately — with the review done right afterwards, never skipped. You get speed where it's safe, and rigour where it counts.

Good change management is invisible. When it's working, you never notice it — changes just happen smoothly, out of hours, without drama. That quiet reliability is the whole point: it's the difference between an IT partner who "moves fast and breaks things" and one you can genuinely trust with your business.
WHY IT MATTERS TO YOU

Enterprise-grade discipline, for your business.

This is the kind of governance usually reserved for the big end of town — and it's exactly the standard we bring to businesses across the Northern Rivers, Gold Coast and Brisbane. The payoff for you is real: far fewer avoidable outages, changes that are safe and reversible, a clear audit trail of who changed what and why, and protection against both honest mistakes and insider risk. It's a big part of what "better, not just cheaper" actually means. See our strategy & governance work →

IT YOU CAN TRUST WITH CHANGE

Does your IT partner have a second set of eyes?

If changes to your systems are made by one person, on the fly, with no way back — that's a risk hiding in plain sight. Book a free IT Health Check and we'll show you how a disciplined change process protects your business day to day.

KEEP READING

Related resources