Skip to main content
Change Risk Intel
Change Risk Intel

Editorial Policy

How Change Risk Intel sources, edits, corrects, and discloses AI assistance in every article we publish.

Last updated

Change Risk Intel exists to help IT change managers, CAB chairs, risk officers, and platform engineers make better decisions about risky changes. That mission only works if the reporting is accurate, sourced, and independent. This page explains how we do that in practice. It is a living document; when we update it we bump the “Last updated” date at the top of the page.

Editorial independence

Change Risk Intel is published by Ennis Studio and is editorially independent from every vendor, sponsor, affiliate partner, and advertiser. Ad placements are inventory-based; sponsors do not choose or review articles. Affiliate links are added by editors after publication, not the other way around, and they never change what an article covers or concludes. No vendor has, or has been offered, prior review of our coverage of them.

Sourcing standards

  • Primary sources first. For security signals we cite CISA, NIST, MSRC, and the affected vendor’s own advisory. For cloud incidents we cite the provider’s public post-incident reports and status pages. For regulation we cite the statute or regulator publication (SEC, OCC, ENISA, CFPB, PCI SSC) rather than second-hand summaries.
  • Vendor documentation over vendor marketing. When we describe how a tool works — for example ServiceNow change flows or Jira Service Management approval rules — we cite the product documentation, not landing pages or datasheets.
  • Named practitioners over anonymous quotes. We prefer on-the-record practitioners with verifiable roles. If we grant anonymity for genuine professional risk, we say so and explain why in the article.
  • No exploit walkthroughs. For CVE and KEV coverage we write from a defender and CAB perspective — what to patch, when to patch, and how to schedule the change — and we do not publish weaponized proof-of-concept detail.
  • Two-source rule for claims that surprise. If a factual claim would change a reader’s operational decision and we cannot find two independent authoritative sources for it within a reasonable time, we either cut the claim or flag it explicitly as unconfirmed.

Bylines and accountability

Articles carry a named byline when a single author is directly accountable for the analysis and interpretation. Where we use our house byline The Change Risk Intel Desk, a named human editor still signs off on the final draft before publication. Author bios link to public professional profiles where available so readers can evaluate expertise directly. We do not use AI-generated pseudonymous bylines.

Use of AI tools

We use AI tools — including large language models and automation platforms — to assist with research, initial drafting, summarization of long primary sources, and quality checks such as broken-link detection and factual consistency review. Every published article is reviewed by a named human editor before it goes live, who is responsible for the accuracy of the final text and for its citations. AI is a research and drafting assistant on this site; it is not the author of record on any article.

If we ever publish an article whose body text is materially AI-generated without meaningful human editorial rewriting, we will label it as such at the top of the page. As of the “Last updated” date on this page, no article on the site meets that description.

Corrections and updates

When we get something wrong, we fix it, and we say so.

  • Typos and formatting. Fixed silently.
  • Factual corrections. The article is updated, an inline correction note is added at the point of the fix, and a dated correction note is appended to the bottom of the piece.
  • Substantive rewrites. If a correction changes the meaning of the piece — for example, a KEV entry we described as urgent turns out to be out of scope for a class of readers — we add a prominent editor’s note at the top of the article and, where relevant, update the URL slug only if the original slug was actively misleading (with a 301 in place).
  • Updates to evolving stories. For stories that continue to develop (an ongoing cloud incident, a live CVE) we date-stamp each update in-line rather than silently overwriting earlier reporting.

To request a correction, email corrections@changeriskintel.com with the URL, the specific passage, and the source that contradicts it. We aim to respond within two business days.

Conflicts of interest

Ben Ennis has previously worked in the ServiceNow ecosystem and operates other Ennis Studio products in adjacent domains (for example CertIndex, in certificate transparency). Where a piece touches on a product, company, or technology in which the author has, or has had, a direct commercial relationship, we disclose that relationship in the article.

Community standards

Comments — where enabled via GitHub Discussions — are moderated. We remove personal attacks, spam, and marketing pitches disguised as comments, and we do not publish comments that misrepresent authoritative sources. Constructive disagreement with our analysis is welcome and often makes the article better.

Contact the editor