Kenio Shirley started where most infrastructure people start: keeping systems running. Over fifteen years he moved from hands-on cloud and platform engineering — networks, identity, deployment pipelines, the unglamorous plumbing that decides whether a product can ship on a Tuesday — into the governance side of the same problem. The transition was not a career change so much as a change in what he was asked to defend. The questions stopped being “can this scale” and started being “can you prove it was always like this, and who approved the change.”
The clearest version of that work happened at TherapyNotes, a behavioral-health EHR and a HIPAA business associate processing electronic protected health information. He owned the change advisory board there in the years leading up to the company’s HITRUST certification — a period in which the obvious move is to tighten everything and accept that delivery slows down. He did the opposite. The change population was classified so routine, well-understood work stopped being re-litigated in a weekly meeting; normal changes moved into the development platform, where the approval and the evidence are produced as a by-product of the work rather than assembled afterwards; and the board’s time was reserved for changes with genuine blast radius or cross-team coupling.
The result was a 30% reduction in change-approval time, with no major incidents and no unanticipated downtime through the period. That combination is the whole argument. The industry treats governance and delivery speed as a trade — you buy safety with latency — and the DORA research programme has been reporting for years that formal external approval boards do not actually buy the safety they charge for. What the frameworks require is that changes are authorized, tested, documented and traceable. None of them require a meeting.
Before that, at ExpenseWatch — an accounts-payable and expense platform whose change controls sit inside its customers’ SOX ITGC scope — he worked through two ownership changes: the Nexonia acquisition in 2016 and the K1 Investment Management roll-up in 2017 that merged four companies into what later became Emburse. Merging control environments is where change management genuinely breaks, and it is the scenario auditors probe hardest in the following year’s testing.
Today he is Change Management Manager at Ivalua, an enterprise source-to-pay platform holding SOC 1 Type 2, SOC 2 Type 2 and ISO 27001, built on NIST SP 800-53. Unusually, Ivalua does not run on a hyperscaler: it operates its own infrastructure across nine data-centre providers in four regions. Coordinating a change across that estate is a sequencing and evidence problem, not a pipeline one. And because the SOC 1 exists so that customers’ auditors can rely on those change controls when forming an opinion on the customers’ own financial reporting, a weak change record does not just fail an internal audit — it propagates outward.
The second thread running through his work is cost. Regulated cloud environments accumulate expense in ways that are invisible on an architecture diagram and obvious on an invoice: log retention set to “forever” because nobody wanted to argue with an auditor, duplicate non-production environments kept for a scope boundary that moved two years ago, isolation implemented with dedicated infrastructure where a policy boundary would have satisfied the same control. The same instrumentation that makes change evidence automatic is what makes those costs visible.