Skip to content
Use cases · when, what, and the limit

What you can do with Déjà, and where each one stops.

Each row says when it applies, what Déjà does, and what you can then do. Each carries its status and its limit in the same place, and links to the page that says more.

Déjà does 14 things today, grouped here by the buyer who cares. Five more are not built, and not claimed.

How to read a row
Available, demonstrated
Built, and shown end to end by us on a real event.
Available
Built and running in the product, on every plan. Only a row marked demonstrated claims we have shown it end to end.
Available on named tiers
As available, on the plans the row names and only those.
Beta
Built to the vendor's documented API, and not yet validated against a live instance by us.

The measured standing of each connection is on the status register.

01 · Audit

For audit: evidence you can test.

Internal audit, IT audit and the external firm they work with.

  • U1Available, demonstrated

    Name the change behind a field break

    When
    A Sentry error names a field that a merged GitHub pull request removed, renamed or retyped.
    Déjà does
    Scores each recorded change to that field in the last 30 days on eight published weights. At 0.80 or above it issues a signed attribution receipt (R1) naming the pull request and its score; from 0.60, a signed low-confidence receipt (R1-L) for you to confirm or reject.
    So you can
    Show an examiner which change the incident was tied to, as recorded at the time.

    Limit. One failure mode only: a removed, renamed or retyped field. Attribution reads Python, TypeScript and JavaScript source and .proto and .avsc schemas; Java, C# (.NET) and Go have no parser. The alerts that can name a field come from Sentry, Splunk On-Call and Alertmanager · Grafana.

    Read more · The engine
  • U2Available

    Show what could not be attributed, for scored sources

    When
    An alert from Sentry, Datadog, Splunk On-Call or Alertmanager · Grafana reaches scoring and cannot be tied to a change: it names no field, no change clears the threshold, or a check stops scoring.
    Déjà does
    Issues a signed no-attribution receipt (R1-N) recording the lookback, how many pull requests it examined and the highest score, with the reason beside it.
    So you can
    Show that the period was watched, not only the incidents where a cause was found.

    Limit. Scored sources only. Alerts from New Relic, Dynatrace, Honeycomb, AppDynamics and Splunk (alerts) are received but not scored yet, so they get no receipt, and whether PagerDuty, AWS CloudWatch, Azure Monitor, Google Cloud Monitoring, incident.io, Rootly and FireHydrant incidents reach scoring is still being checked.

    Read more · Receipt types
  • U3Available

    Hand evidence to your auditor

    When
    SOC 2, NYDFS Part 500 or ISO 27001 fieldwork starts.
    Déjà does
    You open a scoped engagement that expires (90 days by default, at most 365). Your auditor opens a token link with no Déjà account, sees the receipts in scope, downloads the period report with its signed manifest and checks it with dsr-verifier-cli.
    So you can
    Hand over evidence with no screenshots and no vendor login, and have it checked on the auditor's own machine.

    Limit. The Primary Owner, an Owner, an Admin or a Compliance Lead of the vault can open an engagement, and so can a member whose custom role grants sharing with an external auditor. The period report packs R1, R1-L and R1-N receipts; other types in scope are listed in the portal, not packed. dsr-verifier-cli is in early access for customers. [Awaiting owner: public release of the verifier CLI]

    Read more · For auditors
02 · Security

For security: a vendor you can watch.

The CISO's team and third-party risk, reviewing Déjà as a vendor.

  • U8Available

    Evidence configuration changes

    When
    An admin rotates a signing key, changes SSO, connects a tool or opens an audit engagement.
    Déjà does
    Writes the change as a signed governance receipt (RG), chained behind your signed genesis receipt. The integrity monitor checks that chain every 15 minutes.
    So you can
    Evidence access and configuration control over Déjà from the same ledger as the incidents.

    Limit. A governance receipt's signed bytes hold the change type, who made it and hashes of the state before and after, not the settings themselves.

    Read more · Receipt types
  • U9Available

    Approve Déjà's own access to you

    When
    Déjà support needs to look at your account.
    Déjà does
    A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors.
    So you can
    Evidence vendor-access control for third-party risk.

    Limit. This covers reads through Déjà's staff console. It is not a statement about database access outside the console.

    Read more · Security & trust
  • U10Available

    Watch Déjà from your SOC

    When
    Your security team wants Déjà's activity in the SIEM.
    Déjà does
    Your organisation's audit log is posted to an HTTPS address you choose. Each POST carries an HMAC-SHA256 Deja-Signature header, and adding, resuming or re-keying a stream is a governance receipt.
    So you can
    Monitor the vendor with the tools you already run.

    Limit. No SIEM has been tested by name: the stream goes to any HTTPS receiver you run. It is not a receipt, and it is not in the ledger.

    Read more · Security & trust
  • U11Available

    Run access from your identity provider

    When
    People join and leave through your identity provider.
    Déjà does
    Your identity provider adds, updates and suspends members through SCIM 2.0, with a token Déjà issues. Removing a member stays on the Team page. Each change to the token is a governance receipt. Sign-in is SAML with Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, PingIdentity or JumpCloud, or OIDC with Auth0 or Okta, or any SAML 2.0 or OIDC provider. MFA is required on every paid plan, after a 14-day enrolment grace.
    So you can
    Meet access reviews without a second user list.

    Limit. SCIM suspends a member rather than removing them; removal stays on the Team page. The setup marks PingIdentity and JumpCloud as beta.

    Read more · Security & trust
  • U12Available on Enterprise and Sovereign

    Hold the signing key yourself

    When
    Policy says signing keys live in your own KMS.
    Déjà does
    A vault signs with your own AWS KMS key, RSA-PSS or ECDSA, through a cross-account role with an external ID, with scheduled rotation.
    So you can
    Hold the key that signs your evidence.

    Limit. AWS KMS only: Azure Key Vault and GCP KMS are not implemented. For vaults on their own KMS key, Déjà publishes the current public key of at most one such vault per organisation and no key that has been rotated out, so any other key an auditor needs comes from the customer.

    Read more · Security & trust
03 · Engineering and SRE

For engineering and SRE: the record beside your tools.

The teams who connect Déjà and live with it on call.

  • U6Available

    Time a change by its deploy

    When
    A pull request merges hours before it deploys.
    Déjà does
    Records each production deploy against its commit, from GitHub Actions, CircleCI, Jenkins and other CI, Flux or Argo CD, and times the change from its recorded deploy rather than its merge when weighing how close it came before the incident.
    So you can
    Weigh a change by when it shipped, not when it merged.

    Limit. Deploy anchoring, which drops a change deployed after the incident, is a Déjà deployment setting and is off by default. Without it, such a change stays a candidate, and the attribution receipt records that the gate was off. A change with no recorded deploy is timed from its merge.

    Read more · Integrations
  • U7Available

    See what else changed

    When
    A flag flips or an infrastructure run applies just before an incident.
    Déjà does
    Shows LaunchDarkly, Terraform Cloud and Spacelift changes beside the receipt.
    So you can
    Give reviewers the context beyond code.

    Limit. Shown on a receipt when they happened in the 24 hours before its incident. They do not change what it attributes, and are not part of the signed record.

    Read more · Integrations
  • U14Available

    Read receipts into your own tooling

    When
    You want receipts in your data lake or your own dashboards.
    Déjà does
    A REST API, described in OpenAPI at /api/v1/openapi.json, reads receipts, vaults, engagements, evidence packages, frameworks, service zones and the audit log, and verifies a receipt. Keys are scoped to one vault or the organisation, expire after 30, 90, 180 or 365 days, and are rate limited.
    So you can
    Integrate the record with internal tooling.

    Limit. Its webhook endpoints answer 410 Gone: receipts reach your systems through a vault's webhook destination, set up in Connections. Its only other endpoints take data in, as signals and deploy events, and manage its own keys.

    Read more · Docs
04 · Compliance and GRC

For compliance and GRC: evidence where you file it.

Compliance, regulatory and GRC, who file the evidence and answer for it.

  • U4Beta

    File receipts into your GRC tool

    When
    A receipt is issued in a vault connected to a GRC tool.
    Déjà does
    Files each attribution (R1) and no-attribution record (R1-N) as SOC 2 evidence in Vanta or Drata, or attaches each receipt as evidence to one ServiceNow GRC control or one Archer record.
    So you can
    Have the evidence land in the GRC tool without a person moving it.

    Limit. Each is in beta: built to the vendor's documented API, and not yet validated against a live instance by us.

    Read more · Integrations
  • U5Beta

    Tie an incident to its change ticket

    When
    A pull request deploys under a ServiceNow change number that your pipeline sends with the deploy.
    Déjà does
    Reads exactly that change record from ServiceNow after the deploy, and shows it beside the receipt.
    So you can
    Tie an incident to the approved change it shipped under, for change-management testing.

    Limit. Needs a ServiceNow connection, which is in beta, and a pipeline that sends the change number: Déjà never searches ServiceNow for one. The record is shown beside the receipt, not scored and not in its signed bytes.

    Read more · Integrations
  • U13Available

    Send the committee a recurring summary

    When
    A quarter ends, or a risk committee meets.
    Déjà does
    Sends a scheduled Quarterly Business Review, Monthly Operations Brief, Compliance Officer Brief or Annual Compliance Summary by email to members you choose and to outside addresses, each recorded with who added it and when.
    So you can
    Give the committee the same summary on a schedule, without assembling it by hand.

    Limit. A report is an emailed summary, not a receipt: it is not in the ledger and no engagement packs it. Its kept copy and link expire 90 days after it was last sent.

    Read more · Talk to us
05 · Not claimed

Not built, and not claimed.

These are asked for, and Déjà does not do them today. None of them appears above as something you can do, and none should be read into a row that does.

  • U15

    Resolution receipts at scale

    Narrow, not claimed at scale

    What it would be
    When an incident is resolved and the fix holds or fails, a signed resolution receipt (R2), with a hashed R2-F when a gate fails and a hashed R2-R when it recurs.
    Today
    Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic.
  • U16

    Freeze evidence

    Not built

    What it would be
    Flag a receipt issued while a deploy freeze was in effect.
    Today
    A function that checks for an active freeze exists in the code, and nothing calls it, so no receipt is flagged.
  • U17

    Destruction receipt

    Not built

    What it would be
    When you leave: export, then destruction, then a signed receipt recording the destruction.
    Today
    Tables for retention policies and deletion events exist. Nothing in the product schedules a deletion or issues a receipt for one, and no receipt type records a destruction.
  • U18

    Stall alert

    Not built

    What it would be
    Alert you when a connected source stops sending.
    Today
    Déjà does not yet alert you when a connected source stops sending, and in the ledger a quiet source looks the same as a quiet period. An hourly check exists, but it reads only signals posted to Déjà's own incident endpoint as Sentry or GitHub, and the Sentry and GitHub connections post none.
  • U19

    Cross-repository attribution

    In validation, not claimed

    What it would be
    Attribute an incident in one team's service to a change in another team's repository.
    Today
    In validation. Not claimed until it is demonstrated.

If a row's limit matters to you, ask us before you rely on it.

Ask to see it on your own systems during the trial, and hold us to what you see rather than to this page.