Skip to content
New Signal-based gating for canary steps is live in v2.14 Read the changelog →
← All customer stories
Kestrel Bank

Passed a regulatory audit with segregation-of-duties policies enforced in the pipeline.

“The auditors asked who approved a change in March. It took eleven seconds to answer.”

Marta Ilves Marta Ilves Head of Platform
thrayne.dev/releases/2390

Release 2390

rolling out started 4m 02s ago
  1. build

    24s

  2. test

    1m 12s

  3. staging

    8s

  4. canary

    25%

  5. production

$ thrayne promote api-gateway staging to prod
Service Version
api-gateway v2.14.0 live
checkout v2.14.0 rolling
search-index v2.14.1 queued
billing v2.13.2 live

Pipelines

Three pipeline files, 41 services, one promotion path each.

Pipeline Runs (30d) Success Last run
web-monorepo 412 99.3% 6m ago
platform-services 1,284 98.8% 12m ago
data-jobs 96 100% 1h ago

Environments

Promotion order is fixed. Production requires two approvals.

  • production 2 approvals

    eu-west-1 · 38 services

  • canary

    eu-west-1 · 38 services

  • staging

    eu-west-1 · 41 services

  • dev

    local · 41 services

Industry

Financial services

Headquarters

Tallinn, EE

Size

3,200 employees

Relationship

Customer since 2023

11s
to answer an audit query
2 yr
retained history
100%
changes attributable

The story

How Kestrel Bank moved from where they were to where they are, in their platform team's words.

Connected tools

  • GitLab CI
  • Kubernetes
  • HashiCorp Vault
  • Okta
All integrations →
01

The problem

Every audit began with a two-week evidence-gathering exercise. Proof that the person who wrote a change was not the person who approved it lived across screenshots, ticket comments and email threads, assembled by hand each time. The control existed and was genuinely followed — it simply could not be demonstrated quickly, and an auditor's question about a specific change six months ago could take days to answer.

02

What changed

Segregation of duties became a policy the pipeline enforces rather than a convention people follow: the author of a change cannot approve its promotion, and production requires an approver from a named group mapped out of Okta. Deploy credentials are issued per promotion from Vault and expire, so a standing production credential no longer exists. Every promotion records the checks, the approver and the diff, retained for two years.

03

Where they are now

The audit passed with the pipeline itself submitted as the control evidence. A query about any individual change is answered from the release record in seconds rather than days, and every change in the retention window is attributable to a named approver.

“We stopped preparing for audits. The evidence is a by-product of deploying, not a project.”
Marta Ilves Marta Ilves · Head of Platform, Kestrel Bank

Get started

Put every release behind one gate.

Start with a single environment for free. Add the rest when your team is ready — no migration, no rebuild, no second dashboard.

  • Free for one environment
  • SOC 2 Type II
  • Self-host or managed
  • No card required