Dyna Software Brings Git-Style Pull Requests to ServiceNow — and Locks Down How Code Gets Promoted

Dyna Software Brings Git-Style Pull Requests to ServiceNow — and Locks Down How Code Gets Promoted

BackerLeader ●48 ●319 ●504
calendar_today • schedule4 min read

Ron Browning spent years as what one enterprise architecture team called "the exception guy." Every time an internal audit asked for proof that a ServiceNow code change had been properly reviewed, he showed up with a spreadsheet: a link to the update set, a name, a date, a comment, an approval. It worked until an internal auditor looked at the file's save date and asked him directly, "How do I know you didn't just create this file yesterday?"

"That was a total legit question," said Browning, CEO of Dyna Software. ServiceNow had no native way to do the things developers take for granted on other platforms — inline code review, version comparison, threaded comments tied to an actual change. Instead, it used the update set: a single amalgamated XML file that bundles every change into one blob. Useful for deployment. Close to useless for proving who reviewed what, and why.

That gap is what Dyna is closing on September 15, when it formally introduces GuardRails SCM to the ServiceNow community. ServiceNow already has native source control integration with GitHub and GitLab through its DevOps app, so the obvious question is what GuardRails adds on top of existing tools. Browning's answer: "The condensed version is one word — everything." The GitHub and GitLab connections store changes, he said, but they don't make them usable at the level auditors and reviewers actually need. GuardRails surfaces the next layer down — the actual inline diffs, line-level comments, and pull requests — on top of ServiceNow's own on-platform repository.

It's deliberately not Git underneath. "This is all ours," Browning said, but built to mirror the Git experience developers already know from everywhere else. That choice was about avoiding a retraining problem, not cloning a brand: "At least on the calls I've been engaged on, 100% of the time, people see it and go, 'Oh, I know what this is.'" Nobody has to learn how to do a pull request or double-click to leave a comment. They already know.

The AI governance piece stays just as narrow on purpose. GuardRails uses AI for specific tasks like validating CMDB and CSDM alignment — checking that configuration data matches the common data model ServiceNow expects — rather than a general-purpose prompt where a model might miss context it doesn't know to look for. "The key thing is using fixed system prompting so that we're targeting the specific thing and not opening up the opportunity for missing pieces or unnecessary risk being introduced," Browning said. The AI runs through whatever enterprise LLM the customer already uses — typically a self-hosted model on Azure or similar — so no ServiceNow data goes to a third-party model Dyna doesn't control.

Two human checkpoints sit on either side of that AI: one when a developer validates an AI-assisted fix, and a second, broader one at pull-request review. "You only have one button once you're done your work, and that is to do a pull request, which means it has to run through that human gating and validation before it can get promoted," Browning said. That design is intentional — without it, a developer could promote code straight to production. Browning pointed to Vanguard Group: a small central platform team supporting roughly 26 development pods of five to seven developers each, where self-promotion had become a segregation-of-duties failure auditors were flagging. GuardRails removes the option rather than relying on a policy nobody enforces.

On audit, Browning said GuardRails captures more than ServiceNow's own logs do — not just who changed a record and when, but the actual before-and-after version diff, plus monitoring on tables ServiceNow doesn't track at all. Asked directly whether that's more thorough compliance than ServiceNow provides natively, Browning didn't hedge: "Absolutely."

The word Dyna keeps using for this release is continuous, and it contrasts with a compliance process that's entirely manual today. "In that manual situation, you've got starts and stops, you've got gaps and misses, and you ultimately have to rely on the individual to make sure that they've done the right pieces along the way," Browning said. In practice, continuous means checks run in the background while a developer works normally, instead of arriving as a late gut-check right before release.

One Dyna customer — a large U.S. healthcare and retail company running ServiceNow across its customer and patient-facing operations — had gone through three ServiceNow re-platforms in two years before adopting SCM, Browning said, at $7 million to $8 million each, driven partly by technical debt from changes that never got properly reviewed under time pressure. The company's goal was nightly releases, well past the weekly-to-biweekly cadence most ServiceNow shops run. Its central review process used to mean a daily meeting with 15 to 20 people working through a pile of update sets by hand — "I don't know the exact time, but I would assume it's like a two-hour meeting," Browning said. Two to three months into using SCM, that process is down to a release coordinator and an architect working a pull-request queue.

Browning drew a clear, if temporary, line on how far AI should go in this pipeline. Comparing notes with a similar argument Copado recently made about keeping compliance gates deterministic rather than agent-decided, Browning said the limiting factor for AI right now is context — a developer or architect often knows about an upstream integration or a business constraint that never makes it into a prompt. "There will be a point where AI can do and go further with it," he said, "but it's going to have to be a situation where much more in-depth and broader context can come into play." For now, GuardRails keeps a person in that loop. His closing pitch to developers wasn't about control, though — it was about relief: "This isn't job-shattering. This is job enhancing... this gives you the chance to really use AI to accelerate, not just simply enhance your coding ability."

🔥 Join developers growing publicly
Share your knowledge, build in public, and grow your developer presence with a global community.

More Posts

I’m a Senior Dev and I’ve Forgotten How to Think Without a Prompt

Karol Modelski - Mar 19

How to Build a Portfolio Website That Actually Gets You Hired

muhammadfarhan.dev - Aug 21

Helping Clients Move from Pilot to Production: The Agentic AI Governance Playbook

Tom Smithverified - Jun 8

From Prompts to Goals: The Rise of Outcome-Driven Development

Tom Smithverified - Apr 11

Systems Thinking: Thriving in the Third Golden Age of Software

Tom Smithverified - Apr 15
chevron_left
18.9k Points • 871 Badges
258Posts
151Comments
126Connections
LLM Training & Evaluation Specialist with hands-on experience building major AI models. As one of th... Show more

Related Jobs

View all jobs →

Commenters (This Week)

1 comment
1 comment
1 comment

Contribute meaningful comments to climb the leaderboard and earn badges!