Ontech ICTM platform

IT Governance Software

Decide who may do what, write it down as policy, route decisions through the right approvers, and keep a record of every change.

What is IT governance?

IT governance is the framework of policies, decision rights and oversight that makes sure technology supports the organisation's goals, manages risk and complies with its obligations. It defines who decides, how decisions are approved and how they are checked. Ontech ICTM supports it with a policy register, approval workflows, change control, an audit trail and reports.

IT governance sits above day-to-day IT management. Management runs the systems; governance sets the rules they run by and checks that those rules are followed. In practice that means written policies with owners and review dates, clear decision rights for spending and change, and an audit trail that shows what was done and by whom.

Governance often fails in the gaps between documents and systems: a policy is approved but nobody records who has read it, an approval happens by email and is lost, a change goes live without a rollback plan. The controls exist on paper, but there is no evidence that they operate.

ICTM keeps that evidence as part of normal work. Policies are versioned and acknowledged in the system, approvals follow defined rules with delegation and escalation, change requests carry their risk and rollback plans, and write actions are logged in an audit trail with a hash on each entry.

What ICTM does for it governance

Policy register with version history

Maintain IT policies in a register that versions them automatically and keeps a snapshot of each earlier version, so you can show what a policy said at any point.

Policy review sign-off

Record each policy review with the reviewer's sign-off; ICTM then sets the date of the next review so policies do not quietly go out of date.

Policy acknowledgement records

Record who accepted which version of a policy, when, and from which IP address — the evidence auditors ask for when they want proof that a policy has been read. Recording an acknowledgement currently needs the governance-management permission.

Multi-stage approvals

Build approval workflows that need any one approver, all approvers, a majority or a set number of them, with email notifications at each stage.

Conditional routing, delegation and escalation

Trigger extra approval stages on conditions such as a budget above a threshold, let approvers delegate while away, and escalate requests that sit unanswered on a schedule.

Change management

Raise requests for change with their risk assessment and rollback plan, route them through the approval engine, and use asset dependencies to see which services a change could affect.

Audit trail with integrity hashes

Write actions in ICTM are logged, and each audit entry stores a SHA-256 hash of its contents as an integrity check against accidental or casual edits.

Audit anomaly detection

Scheduled, rule-based checks on the audit log flag patterns such as repeated failed logins, mass deletions and unusual out-of-hours activity.

Governance reports

Produce 23 types of report from live ICTM data and export them to CSV, Excel or PDF for committees, auditors and management.

ICTM modules: Governance · Approvals · Change · Audit · Reports

Use cases

Showing policies are read, not just written

Publish a revised acceptable-use policy and record acknowledgement of that exact version by each person who accepts it.

Controlling IT spend

Route purchase requests above a set amount to an additional approver automatically.

Safer changes to core systems

Require a risk assessment, rollback plan and approval before changes to production systems.

Answering the auditor

Show who approved a change, when a policy was last reviewed and what the audit log recorded, from one system.

Oversight for management and committees

Export reports that give an IT or audit committee a current view of the areas it oversees.

Benefits

Evidence as a by-product

Approvals, acknowledgements and changes leave records as they happen.

Clear decision rights

Approval rules encode who may decide what, including thresholds and delegation.

Fewer stalled decisions

Scheduled escalation moves requests that would otherwise wait in an inbox.

Integrity checks on audit entries

Each audit entry stores a hash of its contents, which helps spot accidental or casual edits.

Frequently asked questions

What is the difference between IT governance and IT management?

IT governance sets direction and rules: policies, decision rights, risk appetite and oversight. IT management carries out the day-to-day work within those rules: running systems, handling tickets and delivering projects. Governance asks whether the right things are being done; management makes sure they are done well.

How does ICTM record that staff have accepted a policy?

When a user acknowledges a policy, ICTM stores who accepted it, which version they accepted, the time and the IP address it came from. Because policies are versioned, you can see who has accepted the current version and who has only accepted an earlier one. Recording an acknowledgement currently needs the governance-management permission, so grant it to the people who must acknowledge or record acceptances on their behalf.

How is the ICTM audit trail protected?

Write actions are logged, and each audit entry is stored with a SHA-256 hash calculated from its contents, so an entry edited without updating its hash no longer matches. The hash is not keyed and entries are not chained, so it guards against accidental or casual edits rather than a determined administrator with database access. Old entries are removed according to your retention settings.

Can approvals be delegated when someone is away?

Yes. Approvers can delegate to a colleague, and requests that are not acted on can be escalated on a schedule. Workflows can require any one approver, all of them, a majority or a set number, and can add stages automatically when a condition such as a budget threshold is met.

Which governance frameworks does ICTM follow?

ICTM is not built around a single governance framework. It provides the building blocks most frameworks expect — policies with owners and reviews, defined approval rights, change control, an audit trail and reports — and its compliance module maps controls to standards such as ISO/IEC 27001 and NIST CSF 2.0.

See it governance in Ontech ICTM

Book a walkthrough with the Ontech team, or start a free trial and explore the platform yourself.