Home
cd ../playbooks
Operations & ComplianceIntermediate

Change Request Manager

Change management requests with impact analysis, approval workflows, and rollback plans

10 minutes
By AnthropicSource
#change-management#impact-analysis#rollback#operations

Every system change is a risk — but writing the impact analysis, approval workflow, communication plan, and rollback procedure takes longer than the change itself. So changes happen without proper documentation, and when things break, nobody knows how to undo them.

Who it's for: IT managers implementing system changes, operations leads managing process updates, compliance officers requiring change documentation, project managers controlling scope changes, DevOps teams managing production deployments

Example

"Create a change request for migrating our CRM to the new platform" → Structured change request with impact analysis across users/systems/processes, risk assessment, step-by-step implementation plan, stakeholder communication plan, and rollback procedure

CLAUDE.md Template

New here? 3-minute setup guide → | Already set up? Copy the template below.

# Change Request Manager

Create a structured change request with impact analysis, risk assessment, and rollback plan.

## Change Management Framework

Apply the assess-plan-execute-sustain framework when building the request:

### 1. Assess
- What is changing?
- Who is affected?
- How significant is the change? (Low / Medium / High)
- What resistance should we expect?

### 2. Plan
- Communication plan (who, what, when, how)
- Training plan (what are needed, how to deliver)
- Support plan (help desk, champions, FAQs)
- Timeline with milestones

### 3. Execute
- Announce and explain the "why"
- Train and support
- Monitor adoption
- Address resistance

### 4. Sustain
- Measure adoption and effectiveness
- Reinforce new behaviors
- Address lingering issues
- Document lessons learned

## Communication Principles

- Explain the **why** before the **what**
- Communicate early and often
- Use multiple channels
- Acknowledge what's being lost, not just what's being gained
- Provide a clear path for questions and concerns

## Output

```markdown
## Change Request: [Title]
**Requester:** [Name] | **Date:** [Date] | **Priority:** [Critical/High/Medium/Low]
**Status:** Draft | Pending Approval | Approved | In Progress | Complete

### Description
[What is changing and why]

### Business Justification
[Why this change is needed — cost savings, compliance, efficiency, risk reduction]

### Impact Analysis
| Area | Impact | Details |
|------|--------|---------|
| Users | [High/Med/Low/None] | [Who is affected and how] |
| Systems | [High/Med/Low/None] | [What systems are affected] |
| Processes | [High/Med/Low/None] | [What workflows change] |
| Cost | [High/Med/Low/None] | [Budget impact] |

### Risk Assessment
| Risk | Likelihood | Impact | Mitigation |
|------|-----------|--------|------------|
| [Risk] | [H/M/L] | [H/M/L] | [How to mitigate] |

### Implementation Plan
| Step | Owner | Timeline | Dependencies |
|------|-------|----------|--------------|
| [Step] | [Person] | [Date] | [What it depends on] |

### Communication Plan
| Audience | Message | Channel | Timing |
|----------|---------|---------|--------|
| [Who] | [What to tell them] | [How] | [When] |

### Rollback Plan
[Step-by-step plan to reverse the change if needed]
- Trigger: [When to roll back]
- Steps: [How to roll back]
- Verification: [How to confirm rollback worked]

### Approvals Required
| Approver | Role | Status |
|----------|------|--------|
| [Name] | [Role] | Pending |
```

## Tips

1. **Be specific about impact** — "Everyone" is not an impact assessment. "200 users in the billing team" is.
2. **Always have a rollback plan** — Even if you're confident, plan for failure.
3. **Communicate early** — Surprises create resistance. Previews create buy-in.
README.md

What This Does

Creates structured change requests using an assess-plan-execute-sustain framework. Generates impact analyses across users, systems, processes, and cost — plus risk assessments, implementation plans, communication plans, and rollback procedures.


Quick Start

Step 1: Download the Template

Click Download above to get the CLAUDE.md file.

Step 2: Set Up Your Project

Create a project folder and place the template inside:

change-management/
├── CLAUDE.md
├── requests/       # Change request documents
└── templates/      # Reusable templates

Step 3: Start Working

claude

Say: "Create a change request for migrating our billing system to Stripe"


What Gets Produced

Section Details
Impact Analysis User, system, process, and cost impact ratings
Risk Assessment Likelihood x impact matrix with mitigations
Implementation Plan Steps, owners, timelines, dependencies
Communication Plan Audience, message, channel, timing
Rollback Plan Triggers, steps, and verification
Approvals Required approvers with status tracking

Tips

  • Be specific about impact — "200 users in the billing team" beats "everyone"
  • Always have a rollback plan — Even if you're confident, plan for failure
  • Communicate early — Surprises create resistance; previews create buy-in

Example Prompts

"Create a change request for migrating our billing system to Stripe"
"Draft a change request for switching from Slack to Teams"
"Build a change request for the new PTO policy rollout"
"What's the rollback plan for our database migration?"

$Related Playbooks

Operations & Compliance

CMMC 2.0 Compliance Advisor

Prepare for CMMC 2.0 — Level 1/2/3 scoping, NIST SP 800-171 practices, CUI and FCI protection, SSP and POA&M, SPRS scoring, self-assessment, and C3PAO/DIBCAC readiness for DoD contracts.

10 minutes
Advanced
Operations & Compliance

Compliance Tracker

Track compliance requirements and audit readiness for SOC 2, ISO 27001, and GDPR

10 minutes
Advanced
Operations & Compliance

DORA Resilience Advisor

Meet DORA (Regulation (EU) 2022/2554) for EU financial entities — ICT risk frameworks, incident classification and reporting, TLPT, third-party risk, the Register of Information, and contractual provisions.

10 minutes
Advanced
Operations & Compliance

CSRD Sustainability Reporting Advisor

Meet the EU CSRD and ESRS — scope and threshold analysis, double materiality assessment, ESRS E/S/G disclosures, value-chain reporting, XBRL tagging, assurance, and gap assessments.

10 minutes
Advanced
Operations & Compliance

EU Cyber Resilience Act Advisor

Meet the EU CRA (Regulation 2024/2847) for products with digital elements — product classification, conformity assessment, CE marking, SBOM, vulnerability and incident reporting, and support-period duties.

10 minutes
Advanced
Operations & Compliance

FedRAMP Authorization Advisor

Navigate the full FedRAMP lifecycle — impact levels, system boundary, SSP/SAP/SAR/POA&M, 800-53 controls, 3PAO assessments, continuous monitoring, and readiness for ATO.

10 minutes
Advanced
Operations & Compliance

ISO 27001 Advisor

Run ISO 27001 gap analysis, write policies, build the Statement of Applicability and risk register, apply Annex A controls, and prepare for certification — including the 2013-to-2022 transition.

10 minutes
Intermediate
Operations & Compliance

ISO 42001 AI Management Advisor

Build and certify an AI Management System (AIMS) under ISO/IEC 42001:2023 — AI policy, Annex A controls, AI risk and impact assessments, Statement of Applicability, and lifecycle governance.

10 minutes
Advanced
Operations & Compliance

NIS2 Directive Advisor

Classify essential vs. important entities under EU NIS2, apply Art. 21 risk-management measures, meet Art. 23 incident-reporting timelines, address governance and supply-chain security, and align with ISO 27001.

10 minutes
Intermediate
Operations & Compliance

NIST SP 800-53 Advisor

Select and tailor NIST SP 800-53 Rev 5 controls — all 20 families, Low/Moderate/High baselines, FIPS 199/200 categorization, overlays, privacy and supply-chain controls, RMF integration, and control narratives.

10 minutes
Advanced
Operations & Compliance

NIST AI RMF Advisor

Apply the NIST AI Risk Management Framework (AI RMF 1.0) across its four functions — GOVERN, MAP, MEASURE, MANAGE — to assess AI risk, build profiles, and operationalize trustworthy AI.

10 minutes
Intermediate
Operations & Compliance

NIST CSF Advisor

Assess and improve cybersecurity posture with the NIST Cybersecurity Framework 2.0 — the six functions, implementation tiers, organizational and community profiles, gap assessments, and framework mappings.

10 minutes
Intermediate

Browse all Operations & Compliance playbooks →