top | item 36782597

(no title)

jerdthenerd | 2 years ago

Can someone, anyone, explain to me how this passes SOX scrutiny?

I have issues with business/product team even commenting on PRs because auditors have said that access to GitHub=Access to Codebase.

There are a select few people I would consider granting access to code within our product teams, but without "segregation of duties" clearly defined, I don't think it would fly.

discuss

order

No comments yet.