Xoxoday operates a formal Change Management Procedure that governs all system, process, and infrastructure changes through structured risk assessment, multi-stakeholder approval, pre-production validation, and documented post-implementation review.
Xoxoday’s Change Management Procedure applies to every planned modification across its platforms — from backend infrastructure updates and security patches to feature releases across Xoxoday Empuls, Plum, and Compass. Each change is logged at intake, categorized by risk level and potential business impact, and assigned for structured review before any implementation work begins.
The review and approval workflow involves multiple teams in parallel. IT, security, and product stakeholders evaluate each request against defined risk thresholds before it advances. High-risk changes — such as updates to Xoxoday’s integrations with SAP SuccessFactors, Darwinbox, or Workday — require sign-off from senior stakeholders prior to moving into test environments.
Before any change reaches production, Xoxoday validates it in dedicated pre-production environments that mirror live infrastructure. This stage covers functional testing, regression checks, and performance benchmarking. For changes that affect Xoxoday’s Slack or Microsoft Teams reward delivery workflows, validation includes end-to-end integration testing to confirm notification triggers, redemption flows, and token handling all behave as expected.
Every implementation is scheduled during defined maintenance windows and is accompanied by a documented rollback plan. If a deployment does not meet acceptance criteria during the release window, the rollback plan activates immediately — minimising disruption to your organisation’s rewards, engagement, or incentive programs. This approach directly supports the availability commitments Xoxoday upholds under its SOC 2 Type II attestation and ISO 27001 certification.
After each change, Xoxoday conducts a post-implementation review. Teams verify that stated objectives were met, document any deviations from the plan, and capture lessons learned to improve future release cycles. This feedback loop strengthens both the quality of Xoxoday’s releases and the robustness of its overall security posture over time.
The full procedure gives your organisation confidence that Xoxoday evolves its platform without introducing unplanned downtime, data integrity risks, or security gaps. Whether changes affect reward catalogues, payout workflows, or underlying cloud infrastructure, they follow the same controlled, auditable path from initial request through to post-release sign-off.
Learn more: Xoxoday Help Centre — Technical requirement
Is Xoxoday ISO 27001 and SOC 2 certified?
Xoxoday holds ISO 27001 certification and SOC 2 Type II attestation, confirming independent third-party validation of its information security management controls.
How does Xoxoday handle security incidents?
Xoxoday maintains a formal incident response procedure with defined escalation paths, containment steps, and post-incident review to protect platform and data integrity.