← Agile/Scrum Suite 25 · Governance & Stakeholder

Change Control Log

Download Excel

Ten formal Change Requests were raised on this program — all affecting a baselined commitment (budget or schedule), which is why they went through this formal path rather than ordinary backlog reprioritization (see Change Handling in Agile for where that line sits). All ten were approved and implemented.

Showing all 13 change requests

Who raises a change here follows the role split. Backlog order and scope calls are the Product Owner's (D. Ashworth) — reprioritizing within approved scope needs no CR at all. Cost, schedule and delivery-method changes come from the Agile Delivery Lead or the engineering leads. Approval sits with the Sponsor in every case, because a CR exists only when something touches a baselined commitment. See Roles & Responsibilities.

CR-01
Additional Staging/Load-Test Environment
Implemented
CostRaised: Sprint 4Approved By: M. Delacroix (Sponsor)
Cost Impact
+$18,000
Schedule Impact
None
Scope Impact
None

A. Singh flagged that load-testing the video visit infrastructure against a production-realistic patient volume required a dedicated staging environment separate from the shared dev/test environment already in use — running load tests there risked disrupting both teams' daily work. Requested and approved as a one-time infrastructure cost ahead of Release 1 hardening (Sprint 5).

Outcome if not approved: Load testing would have run against the shared environment, risking test interference for both teams during Release 1's critical hardening sprint. Approved same-week to avoid that risk.
View Full CR Document (CR-01) →
CR-02
Contractor Support for Sprint 7 Data Migration Remediation
Implemented
CostRaised: Sprint 6Approved By: M. Delacroix (Sponsor)
Cost Impact
+$42,000
Schedule Impact
None (absorbed)
Scope Impact
None

Ahead of Sprint 7's full historical record migration, early data-quality spot-checks on the legacy archive surfaced more inconsistent field mappings than the original migration pipeline (built in Sprint 1) was designed to handle automatically. Rather than risk the Sprint 8 cutover date, Anchor requested two short-term contractors for Sprint 7 only to build additional remediation scripts. This is the change referenced as risk R-04 in the RAIDD Log and the Sprint 6 Status Report's Amber budget rating.

Outcome if not approved: Anchor's existing team would have had to absorb the remediation work inside Sprint 7's existing capacity, risking either the migration quality or the Sprint 8 cutover date. Approved to protect the fixed cutover date instead.
View Full CR Document (CR-02) →
CR-03
Extend Pre-Cutover Compliance Review Window (2 Days → 5 Days)
Implemented
ScheduleRaised: Sprint 7Approved By: M. Delacroix (Sponsor) + T. Brannigan (Compliance)
Cost Impact
None
Schedule Impact
Internal only — no program-end slip
Scope Impact
None

The full historical migration's larger-than-planned remediation effort (see CR-02) meant Compliance needed more than the originally planned 2 business days to validate the archive before Release 2 cutover. The Sprint 8 sprint boundary and May 8 go-live date did not move — instead, the final regression-testing window inside Sprint 8 was compressed from 4 days to 1 day to make room. This trade-off was explicitly accepted (not silently absorbed) and logged as an accepted residual risk rather than a schedule slip.

Outcome if not approved: Either the compliance review would have been rushed on the original 2-day window (unacceptable risk on a PHI/patient-safety validation), or the May 8 cutover date would have slipped. The team chose to compress regression testing instead, with Compliance and the Sponsor both explicitly signing off on that trade-off.
View Full CR Document (CR-03) →
CR-04
Add Penetration Testing Vendor Engagement
Implemented
CostRaised: Sprint 2Approved By: M. Delacroix (Sponsor)
Cost Impact
+$25,000
Schedule Impact
None
Scope Impact
None

Compliance flagged that the video-visit feature's PHI handling had never been penetration tested by an independent third party — internal security review alone wasn't sufficient for a patient-facing telehealth feature. A one-time external pen-test engagement was added ahead of Release 1 hardening.

Outcome if not approved: Release 1 would have shipped on internal security review alone, leaving an unverified PHI exposure risk in a patient-facing feature — Compliance would not sign off on go-live without it.
View Full CR Document (CR-04) →
CR-05
Temporary Third Offshore QA Analyst — Team Anchor
Implemented
CostRaised: Sprint 3Approved By: M. Delacroix (Sponsor)
Cost Impact
+$15,000
Schedule Impact
None
Scope Impact
None

Team Anchor's defect backlog grew faster than its two offshore QA analysts (M. Chen, P. Kumar) could burn down ahead of the Release 1 hardening sprint. A third offshore QA analyst was added for Sprints 3-4 only to clear the backlog before hardening began.

Outcome if not approved: The defect backlog would have carried into the hardening sprint, competing directly with hardening work and risking the Release 1 date.
View Full CR Document (CR-05) →
CR-06
Add SMS/Push Notification Vendor (Reminders)
Implemented
ScopeRaised: Sprint 5Approved By: D. Ashworth (Product Owner) + M. Delacroix (Sponsor)
Cost Impact
+$9,000/mo ongoing
Schedule Impact
None
Scope Impact
Adds SMS/push reminders (originally email-only)

Early Release 1 usage data showed email appointment reminders had a materially lower open rate than expected. Team Falcon added a third-party SMS/push notification vendor to supplement email, a scope addition beyond the original PI objective's email-only reminder design.

Outcome if not approved: Appointment no-show rates tied to missed email reminders would have continued at the Release 1 baseline rate through Release 2 and beyond.
View Full CR Document (CR-06) →
CR-07
Delay Android Release 1 by One Sprint (App Store Rejection)
Implemented
ScheduleRaised: Sprint 5Approved By: D. Whitfield (Eng Lead, Falcon) + M. Delacroix (Sponsor)
Cost Impact
None
Schedule Impact
Android only, +1 sprint
Scope Impact
None

Google Play rejected the initial Android submission over a permissions-declaration issue in S. Park's build. Rather than delay the entire Release 1 launch, iOS shipped on schedule and Android followed one sprint later once the resubmission was approved.

Outcome if not approved: Holding both platforms for a synchronized launch would have delayed the entire Release 1 date by a full sprint instead of one platform only.
View Full CR Document (CR-07) →
CR-08
Add WCAG Accessibility Audit Before Release 2
Implemented
CostRaised: Sprint 6Approved By: M. Delacroix (Sponsor)
Cost Impact
+$12,000
Schedule Impact
None
Scope Impact
None

Release 2's full cutover expands the patient-facing surface significantly; an independent WCAG 2.1 AA accessibility audit was added ahead of cutover, since the original scope only included internal accessibility self-review.

Outcome if not approved: Release 2 would have shipped on internal accessibility self-review alone, without independent verification for a substantially larger patient-facing surface.
View Full CR Document (CR-08) →
CR-09
Defer Family Caregiver Proxy Access to Post-Release 2 Backlog
Implemented
ScopeRaised: Sprint 7Approved By: D. Ashworth (Product Owner) + M. Delacroix (Sponsor)
Cost Impact
None
Schedule Impact
None
Scope Impact
Removes a committed PI objective from Release 2

Family Caregiver Proxy Access was an originally committed PI objective for Release 2, but the Sprint 7 data migration remediation (CR-02) and compliance review extension (CR-03) consumed the capacity that feature needed. Formally deferred to the post-cutover backlog rather than silently dropped, since it was a committed PI objective and required Sponsor sign-off to descope.

Outcome if not approved: The team would have had to pull capacity from cutover-critical work to deliver a non-critical feature, risking the Release 2 date itself.
View Full CR Document (CR-09) →
CR-10
Extend Post-Cutover Hypercare Support by Two Sprints
Implemented
CostRaised: Sprint 8Approved By: M. Delacroix (Sponsor)
Cost Impact
+$30,000
Schedule Impact
Extends program end by 2 sprints
Scope Impact
None

Given the legacy decommissioning happening concurrently with cutover, the Sponsor requested extending full-team hypercare support from the standard one sprint to three sprints post-cutover, to absorb any late-surfacing migration issues before the team stood down to steady-state support levels.

Outcome if not approved: The team would have stood down to steady-state support after one sprint, leaving less capacity to respond quickly to any late-surfacing migration issue during the highest-risk post-cutover window.
Summary
Approval Authority (Decision-Rights Tiering)

Backlog reprioritization within approved scope: Product Owner decides directly, no CR needed. Anything affecting the cost baseline, the release date, or a compliance-relevant timeline: Sponsor approval required (and Compliance co-approval when the change touches a PHI/patient-safety review, as in CR-03). This program never required a full Steering Committee vote for a CR — appropriate to its size, compared to the Enrollment & Claims program's heavier approval chain for its $7M baseline.

View Full CR Document (CR-10) →
CR-11
Establish a change control board with per-change approval gates
Declined
Declined. The sprint boundary is already the control point; a CAB in front of it relocates an existing decision to a slower body with less context. The PMO's real need was auditability, met instead by exporting timestamped refinement decisions.
GovernanceApproval Authority: Sponsor
View Full CR Document (CR-11) →
CR-12
Raise sprint commitment to close the release burnup gap
Declined
Declined. Velocity is an observation, not a lever — raising the commitment changes the chart, not the capacity. Two lowest-value epics cut instead, closing 31 of the 40 points.
ScheduleApproval Authority: Sponsor
View Full CR Document (CR-12) →
CR-13
Add offline mode to the MVP release
Deferred
Deferred, not declined. Full offline editing needs a conflict-resolution model that cannot be responsibly hardened inside the MVP window. Read-only offline cache pulled forward so field users are not left with nothing at launch.
ScopeApproval Authority: Sponsor
View Full CR Document (CR-13) →