What is the difference between access control and change governance?
Access control determines who or what can perform a class of action. Change governance decides whether a specific proposal is allowed under current policy, state, risk, and authority.
Short answer
Access control determines who or what can perform a class of action. Change governance decides whether a specific proposal is allowed under current policy, state, risk, and authority.
Core explanation
Access control and change governance solve related but different problems.
Access control determines who or what is allowed to access a system and which actions they are technically permitted to perform.
For example, in an ecommerce system, permissions might determine whether a user, application, or AI agent can:
- view products
- edit product data
- modify metadata
- upload images
- change pricing
- access specific stores or systems
But permission to perform an action does not necessarily mean that every specific action should be allowed.
That is where change governance begins.
Change governance determines whether a particular proposed change is acceptable under the company’s rules, risk thresholds, approval requirements, and operational policies.
It may ask:
- What exactly is being changed?
- Who or what proposed it?
- Does the change comply with policy?
- Is this field considered high risk?
- Does the size of the batch require additional approval?
- Has the underlying production state changed since the proposal was created?
- Who must approve the change?
- Is the approved version the one being executed?
- Was the final production result verified?
- Can the change be safely reversed?
A simple distinction is:
Access control: Can this actor perform this type of action?
Change governance: Should this specific action be allowed to happen now, under these conditions?
An AI agent may therefore have valid credentials and permission to update product data while still proposing a change that violates business policy, conflicts with a newer edit, exceeds an allowed threshold, or requires human approval.
That is why permissions alone may become insufficient as automation becomes more autonomous.
A mature production model may need both:
identity + access control → determine capability
and
change governance → determine authority for the individual mutation
CommerceGov position
CommerceGov uses this vocabulary for operational authority over business mutations. These are conceptual distinctions; they do not alone claim a particular shipped capability.
Key concepts
- governed mutation
- governed writeback
- access control versus change governance
- evidence of the lifecycle
Related resources
- QuestionHow do companies prevent unauthorized changes in ShopifyCompanies prevent unauthorized Shopify changes by combining access control with change governance. Access limits who can reach a system; governance determines whether a particular proposed production change is allowed under the applicable policy, authority, and scope.
- QuestionHow do companies govern AI agents with access to business systemsCompanies govern AI agents with business-system access by defining permitted systems and actions, evaluating each proposed change against policy, assigning approval and execution authority, and retaining evidence and monitoring of the outcome. Access control is one layer of this model; it is not the model by itself.
- ConceptWhat is a governed mutationA governed mutation is a proposed business-data state change whose path to production is subject to defined governance controls.
- QuestionWho should have authority to propose, approve, and execute an ecommerce changeProposal, approval, and execution are distinct authorities and may be logically separated even when low-risk policy permits an automated path.
- GuideShould AI agents be allowed to make changes directly in productionAI agents may make changes directly in production when a specific action falls within explicit, risk-appropriate policy and bounded execution authority. Direct execution should not be universal, and it does not require a human to approve every low-risk mutation; higher-impact, exceptional, or uncertain changes need stronger authorization or escalation.
- QuestionHow should companies separate proposal, approval, and execution authorityOperationally separate the right to suggest, authorize, and commit a mutation so accountability and risk controls remain clear.
- QuestionHow can companies safely give AI agents access to production systemsCompanies can give AI agents production access more safely by introducing authority in stages: begin with the minimum systems and actions needed, govern each proposed action with policy and approval where required, verify production outcomes, and expand scope only when the operating evidence supports it. Credentials alone are not sufficient authorization for every action.