Heroku logo

Heroku

Access
Cloud Provider

Mycroft inventories Heroku team and app access to show who can deploy to production, and records how pipelines separate environments.

Deploying to production can be a single push, and collaborator lists outlive the engagements that created them. Mycroft reads membership, pipeline stages, release history and the add-ons attached to each app.

How Mycroft connects to Heroku

How it connects
You authorize Mycroft through Heroku OAuth.
What Mycroft can access
The OAuth grant carries Heroku's global scope, which is broad by Heroku's design. Mycroft uses it to read team and app membership and does not write to your apps.

Which controls Heroku evidence maps to

Each row is a control an auditor tests and the specific artifact Mycroft collects from Heroku to satisfy it. Collection runs on a schedule and every result is timestamped.

Heroku compliance control mappings and the evidence Mycroft collects for each
FrameworkControlWhat it requiresEvidence collected from Heroku
SOC 2CC6.1Logical access controls restrict access to information assets.Team member and per-app collaborator inventory with role, plus two-factor authentication enforcement status on the team.
SOC 2CC6.3Access is limited to least privilege and removed when no longer needed.Collaborators holding deploy rights on production apps, reconciled against the current workforce roster from your HRIS or identity provider.
SOC 2CC8.1Changes are authorized, tested and approved before deployment.Pipeline stage configuration with review and staging apps, plus release history showing who promoted each deploy and when.
ISO 27001A.8.31Development, test and production environments are separated.Pipeline stage mapping demonstrating distinct review, staging and production apps with separate configuration.
ISO 27001A.5.18Access rights are provisioned, reviewed and removed.Collaborator lists surfaced in the periodic user access review with reviewer decisions recorded.
ISO 27001A.5.23Information security for the use of cloud services is managed.Add-on inventory identifying third-party data processors attached to each app, feeding vendor risk assessment.

What Mycroft collects automatically

Gathered from Heroku on a schedule, dated and stored against the controls above.

  • Heroku team roster with roles and two-factor authentication enforcement
  • Per-app collaborator lists showing who can deploy to production
  • Pipeline configuration with review, staging and production stages
  • Release history: what was promoted, by whom, and when
  • Add-on inventory per app, identifying attached third-party services
  • Dyno and formation configuration per environment

Manual work this removes

The tasks that disappear from someone's quarter once Heroku is connected.

  • Opening each app's access settings to build a collaborator list for the review
  • Recording which add-ons are attached to which app for the vendor inventory
  • Documenting how staging is separated from production
  • Identifying contractors who retain deploy access to production apps

Heroku and Mycroft: frequently asked questions

The Heroku OAuth grant carries Heroku's global scope, which is broad by Heroku's design rather than something Mycroft narrows. Mycroft uses it to read team and app membership for access reviews and does not write to your apps. Where config var exposure matters to a security review, it is worth confirming the current behaviour with Mycroft.
Through the pipeline. Mycroft records the stage configuration (that a production app is promoted from staging rather than pushed to directly) and the release history showing who promoted each deploy. Together with the pull request record from your code repository, that covers the authorization and approval an auditor tests under SOC 2 CC8.1.
Each add-on is a third party with access to your application's data, which makes it in scope for vendor risk management under SOC 2 CC9.2 and ISO 27001 A.5.19. Pulling the inventory automatically stops the vendor register from drifting out of date the moment an engineer provisions something new.

We turn the compliance nightmare into a dream

Talk to us