
Heroku
Access
Cloud Provider
Mycroft inventories Heroku team and app access to show who can deploy to production, and records how pipelines separate environments.
Deploying to production can be a single push, and collaborator lists outlive the engagements that created them. Mycroft reads membership, pipeline stages, release history and the add-ons attached to each app.
How Mycroft connects to Heroku
- How it connects
- You authorize Mycroft through Heroku OAuth.
- What Mycroft can access
- The OAuth grant carries Heroku's global scope, which is broad by Heroku's design. Mycroft uses it to read team and app membership and does not write to your apps.
Which controls Heroku evidence maps to
Each row is a control an auditor tests and the specific artifact Mycroft collects from Heroku to satisfy it. Collection runs on a schedule and every result is timestamped.
| Framework | Control | What it requires | Evidence collected from Heroku |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access controls restrict access to information assets. | Team member and per-app collaborator inventory with role, plus two-factor authentication enforcement status on the team. |
| SOC 2 | CC6.3 | Access is limited to least privilege and removed when no longer needed. | Collaborators holding deploy rights on production apps, reconciled against the current workforce roster from your HRIS or identity provider. |
| SOC 2 | CC8.1 | Changes are authorized, tested and approved before deployment. | Pipeline stage configuration with review and staging apps, plus release history showing who promoted each deploy and when. |
| ISO 27001 | A.8.31 | Development, test and production environments are separated. | Pipeline stage mapping demonstrating distinct review, staging and production apps with separate configuration. |
| ISO 27001 | A.5.18 | Access rights are provisioned, reviewed and removed. | Collaborator lists surfaced in the periodic user access review with reviewer decisions recorded. |
| ISO 27001 | A.5.23 | Information security for the use of cloud services is managed. | Add-on inventory identifying third-party data processors attached to each app, feeding vendor risk assessment. |
What Mycroft collects automatically
Gathered from Heroku on a schedule, dated and stored against the controls above.
- Heroku team roster with roles and two-factor authentication enforcement
- Per-app collaborator lists showing who can deploy to production
- Pipeline configuration with review, staging and production stages
- Release history: what was promoted, by whom, and when
- Add-on inventory per app, identifying attached third-party services
- Dyno and formation configuration per environment
Manual work this removes
The tasks that disappear from someone's quarter once Heroku is connected.
- Opening each app's access settings to build a collaborator list for the review
- Recording which add-ons are attached to which app for the vendor inventory
- Documenting how staging is separated from production
- Identifying contractors who retain deploy access to production apps
Heroku and Mycroft: frequently asked questions
Does Mycroft read our Heroku config vars?
How does Heroku evidence change management?
Why does the add-on list matter for compliance?
We turn the compliance nightmare into a dream
Talk to us


