01 / Source and scope
Who acts, and what changes?
Financial entity agent operating an ICT service. Financial entity ICT governance and incident authority.
Change a production configuration or restore a service.
02 / Action-time control
Make the requested effect testable.
DORA imposes ICT risk, incident, testing and third-party duties on in-scope entities. Gate production changes and record incident-scoped emergency authority without treating automation as an exemption.
03 / Evidence and responsibility
Permission, execution, and outcome are separate.
Incident, change approval, decision, deployment, recovery and test evidence.
ProofGrid can supply a decision and evidence layer; the financial entity owns DORA governance and reporting.
Primary source