Xentrl Assurance governs change to your Anaplan landscape and produces the evidence as a byproduct of the work rather than as a project that follows it.
Assurance is built around one question: was what's running approved. Whether the application computes correctly is a different question, owned by the people and tools that test it, and Assurance is built to sit alongside them.
What a promotion leaves behind
Every governed promotion produces a single record, retrievable in one action and exportable. It is assembled as the promotion happens rather than reconstructed afterward.
It answers what an auditor asks, in the order they ask it: what changed, who authorized it, what it was for, what it was compared against, and what state the landscape was in when it happened.
Seven steps, in order, each recorded with its timestamp and the person who performed it. The sequence does not start until both approvals are in place, and completing it returns the models to service.
Approved to schedule, then approved to initiate. The team is notified and the models are taken offline.
Nothing. The governance report is complete the moment the promotion is, with no assembly step and nobody to chase.
Checklists are configured per release, with evidence attached where the business requires it. Several promotions can be scheduled and approved together and executed at different times.
A true difference, at model level
Specify a workspace, a model, and a revision tag, and read what actually changed. Modules, lists, processes, roles, and line items, added and changed, down to formula, summary method, data type, and decimal places, with the previous and the new value side by side.
Comparison and summary reports are generated from it, and the comparison made at promotion time is retained with the governance report.
The activity record, in one place
A combined activity record across the landscape, filterable by category. Each entry records what was acted on, the action, who took it and in what role, the outcome, and the time, and opens to the full entry.
| Object | Action | User | Role | Time | Outcome |
|---|---|---|---|---|---|
| Promotion | Update | Dana Whitfield | Promotion Manager | 10/02/2026, 3:21 PM | Success |
| Release | Update | Dana Whitfield | Promotion Manager | 10/02/2026, 3:21 PM | Success |
| Approval | Update | Marcus Reyes | Project Manager | 10/02/2026, 3:20 PM | Success |
| Promotion | Update | Dana Whitfield | Promotion Manager | 10/02/2026, 3:20 PM | Success |
| Approval | Update | Marcus Reyes | Project Manager | 10/02/2026, 3:19 PM | Success |
| Promotion | Create | Priya Natarajan | Construction Manager | 10/02/2026, 3:18 PM | Success |
| Release | Update | Priya Natarajan | Construction Manager | 09/30/2026, 2:31 AM | Success |
A closed loop
Changes that reach a governed environment outside the governed process are identified within minutes, assigned to an owner, and closed with a reason that stays on the record. A promotion run directly in Anaplan, a revision tag applied by hand, a change ported by another route: each becomes an event with a name against it.
These are ordinary operational actions taken by people with the rights to take them. The control is not that they are prevented. It is that each one is recognized, explained by a named person within a defined window, and carried into the record with its reason attached.
When a promotion fails, a rollback is started from the promotion record, the revision tag to restore is selected, and the rollback runs as a governed sequence with its own record.
A ported change is still a change reaching the next environment, so it is governed like any other. Restore and unlink are supported for the maintenance development pattern and the back-port to main development that follows it.
Work items from your change management system are imported and attached to the revision tag when it is created, so they travel with the promotion and roll into the release notes.
Topology is configured once per release, with each node bound to a live model and marked aligned or behind. Releases close as completed, cancelled, or failed, with release notes confirmed before closing. The map itself is on the pipeline map page.
Utilization across every workspace in the tenant, monitored against a threshold the tenant owner sets, and checked as part of the promotion so a promotion is only attempted into a workspace with room for it.
Process Authority
Authorization becomes a precondition of promotion rather than a record kept alongside it. The requester, the approver, and the person executing the promotion are held as distinct recorded roles, and the approval is bound to the specific promotion.
Out-of-Process Detection
Changes that reached an environment without moving through the governed process are identified within minutes, raised as events with an owner and an acknowledgment window, and closed with a reason that stays on the record.
State VerificationExpected 2027
Independent comparison of the running state against a baseline held outside Anaplan, with each pass producing a dated record of what was compared and what it found.
How it connects
Process Authority and Out-of-Process Detection run in the cloud, connecting to your tenant through Anaplan's published APIs. Nothing is installed in your environment for either layer.
Connection is by a certified service user that you create and control in your own tenant, at a permission level we specify in writing before you grant it. That service user is the only connection Assurance holds to your tenant.
Assurance reads the landscape and initiates promotions through Anaplan's own mechanism. It writes no data values into a model. Every action it takes in your tenant, including promotions, backups, and taking models offline, runs through the certified service user and is recorded.
The Verifier is deployed on premises, because verification requires access to state that is better kept inside your environment. It performs its analysis locally. Only a summary of findings returns to the cloud: what drifted, where, and how significant. The model detail and data it compared stay in your environment.
What we need from you
ALM performs the promotion and continues to work exactly as it does today. Assurance governs whether it proceeds and under what authority.
Roles, selective access, and workspace permissions are administered in Anaplan and stay there, under the people who own them.
Your change management system continues to hold the work. Assurance imports work items from your change management system and associates them with the promotions that carry them.
Connection is by a certified service user you create and control, at a permission level specified in writing. Assurance writes no data values into a model.