Xentrl Assurance Product wireframe v5.5

One promotion. One record. One click.

Xentrl Assurance governs change to your Anaplan landscape and produces the evidence as a byproduct of the work rather than as a project that follows it.

Assurance is built around one question: was what's running approved. Whether the application computes correctly is a different question, owned by the people and tools that test it, and Assurance is built to sit alongside them.

What a promotion leaves behind

Every governed promotion produces a single record, retrievable in one action and exportable. It is assembled as the promotion happens rather than reconstructed afterward.

It answers what an auditor asks, in the order they ask it: what changed, who authorized it, what it was for, what it was compared against, and what state the landscape was in when it happened.

Governance reportOne promotion, one record, exportable
PromotionIdentifier, status, result, scheduled time and estimated duration
RouteSource and target model, source and target workspace, phase
PeopleWho created it, who approved the schedule, who approved initiation, who executed each step
AuthorizationApproval for schedule and approval for initiation, held with the promotion rather than alongside it
What it carriedRevision tag description carrying the work items and their descriptions
Revision tagsThe tag synced and the tag previously on the target
ComparisonThe comparison summaries generated at promotion time, stored as part of the record
BackupWhich model was backed up, when, by whom, and the confirmation that it completed before the promotion continued
ChecklistsPre-flight and post-promotion checks, with evidence and attestation where required
IntegrationsConfirmation that integrations were turned off and turned back on
CapacityWorkspace utilization at the time of the promotion
NotesPromotion notes and closing notes
ExecutionEvery step in the sequence, in order, with its timestamp and the user who performed it

How a governed promotion runs

Seven steps, in order, each recorded with its timestamp and the person who performed it. The sequence does not start until both approvals are in place, and completing it returns the models to service.

1Pre-flight checks
2Revision tag selection
3Comparison report
4Backup target model
5Sync changes
6Post checks and notifications
7Complete promotion: models return to service and integrations are confirmed running
Before step one

Approved to schedule, then approved to initiate. The team is notified and the models are taken offline.

After step seven

Nothing. The governance report is complete the moment the promotion is, with no assembly step and nobody to chase.

Checklists are configured per release, with evidence attached where the business requires it. Several promotions can be scheduled and approved together and executed at different times.

Metadata diffs

A true difference, at model level

Specify a workspace, a model, and a revision tag, and read what actually changed. Modules, lists, processes, roles, and line items, added and changed, down to formula, summary method, data type, and decimal places, with the previous and the new value side by side.

Comparison and summary reports are generated from it, and the comparison made at promotion time is retained with the governance report.

Changes across modules, lists, processes, roles, and line items, with each difference readable at the property level.
Changes across modules, lists, processes, roles, and line items, with each difference readable at the property level.

Audit history

The activity record, in one place

A combined activity record across the landscape, filterable by category. Each entry records what was acted on, the action, who took it and in what role, the outcome, and the time, and opens to the full entry.

All ▾Execution Approval Backport Model Backup Port Changes Promotion Restore & Unlink Revision Tag Rollback ▸Resources...
ObjectActionUserRoleTimeOutcome
PromotionUpdateDana WhitfieldPromotion Manager10/02/2026, 3:21 PMSuccess
ReleaseUpdateDana WhitfieldPromotion Manager10/02/2026, 3:21 PMSuccess
ApprovalUpdateMarcus ReyesProject Manager10/02/2026, 3:20 PMSuccess
PromotionUpdateDana WhitfieldPromotion Manager10/02/2026, 3:20 PMSuccess
ApprovalUpdateMarcus ReyesProject Manager10/02/2026, 3:19 PMSuccess
PromotionCreatePriya NatarajanConstruction Manager10/02/2026, 3:18 PMSuccess
ReleaseUpdatePriya NatarajanConstruction Manager09/30/2026, 2:31 AMSuccess

Out-of-process events

A closed loop

Changes that reach a governed environment outside the governed process are identified within minutes, assigned to an owner, and closed with a reason that stays on the record. A promotion run directly in Anaplan, a revision tag applied by hand, a change ported by another route: each becomes an event with a name against it.

These are ordinary operational actions taken by people with the rights to take them. The control is not that they are prevented. It is that each one is recognized, explained by a named person within a defined window, and carried into the record with its reason attached.

Found, not sampledDetection covers every change of the kinds it monitors, rather than a sample of them.
Someone answers for itEach event goes to the person who ran that release, inside a window the tenant sets once and applies to everyone.
The reason survivesEvents are closed with a reason and a justification. Later corrections append rather than overwrite, so the first answer stays visible.
The pattern is visibleReasons aggregate across releases, so what keeps driving changes outside the process becomes something you can fix.

What else is in the product

Controlled rollback

When a promotion fails, a rollback is started from the promotion record, the revision tag to restore is selected, and the rollback runs as a governed sequence with its own record.

Ported changes and back-porting

A ported change is still a change reaching the next environment, so it is governed like any other. Restore and unlink are supported for the maintenance development pattern and the back-port to main development that follows it.

Work items on the record

Work items from your change management system are imported and attached to the revision tag when it is created, so they travel with the promotion and roll into the release notes.

Releases and topology

Topology is configured once per release, with each node bound to a live model and marked aligned or behind. Releases close as completed, cancelled, or failed, with release notes confirmed before closing. The map itself is on the pipeline map page.

Workspace capacity

Utilization across every workspace in the tenant, monitored against a threshold the tenant owner sets, and checked as part of the promotion so a promotion is only attempted into a workspace with room for it.

Three layers

Process Authority

Authorization becomes a precondition of promotion rather than a record kept alongside it. The requester, the approver, and the person executing the promotion are held as distinct recorded roles, and the approval is bound to the specific promotion.

Out-of-Process Detection

Changes that reached an environment without moving through the governed process are identified within minutes, raised as events with an owner and an acknowledgment window, and closed with a reason that stays on the record.

State VerificationExpected 2027

Independent comparison of the running state against a baseline held outside Anaplan, with each pass producing a dated record of what was compared and what it found.

How it connects

Process Authority and Out-of-Process Detection run in the cloud, connecting to your tenant through Anaplan's published APIs. Nothing is installed in your environment for either layer.

Connection is by a certified service user that you create and control in your own tenant, at a permission level we specify in writing before you grant it. That service user is the only connection Assurance holds to your tenant.

Assurance reads the landscape and initiates promotions through Anaplan's own mechanism. It writes no data values into a model. Every action it takes in your tenant, including promotions, backups, and taking models offline, runs through the certified service user and is recorded.

The Verifier is deployed on premises, because verification requires access to state that is better kept inside your environment. It performs its analysis locally. Only a summary of findings returns to the cloud: what drifted, where, and how significant. The model detail and data it compared stay in your environment.

Expected 2027
Assurance, in the cloudProcess Authority and Out-of-Process Detection. Connects only through the certified service user you control. Reads the landscape and initiates promotions.
findings only
The Verifier, in your environmentHolds the detailed baseline. Performs the comparison locally. The detail stays where it is. Expected 2027.

What we need from you

  • A certified service user in your Anaplan tenant, at a permission level we specify in writing
  • A named owner for approval routing, and a named owner for out-of-process events
  • Your existing change process, which we configure Assurance to follow

Where it fits

With ALM

ALM performs the promotion and continues to work exactly as it does today. Assurance governs whether it proceeds and under what authority.

With Anaplan's access model

Roles, selective access, and workspace permissions are administered in Anaplan and stay there, under the people who own them.

With your ITSM system

Your change management system continues to hold the work. Assurance imports work items from your change management system and associates them with the promotions that carry them.

Connection is by a certified service user you create and control, at a permission level specified in writing. Assurance writes no data values into a model.