What you can do with Déjà, and where each one stops.
Each row says when it applies, what Déjà does, and what you can then do. Each carries its status and its limit in the same place, and links to the page that says more.
Déjà does 14 things today, grouped here by the buyer who cares. Five more are not built, and not claimed.
- Available, demonstrated
- Built, and shown end to end by us on a real event.
- Available
- Built and running in the product, on every plan. Only a row marked demonstrated claims we have shown it end to end.
- Available on named tiers
- As available, on the plans the row names and only those.
- Beta
- Built to the vendor's documented API, and not yet validated against a live instance by us.
The measured standing of each connection is on the status register.
For audit: evidence you can test.
Internal audit, IT audit and the external firm they work with.
- U1Available, demonstrated
Name the change behind a field break
- When
- A Sentry error names a field that a merged GitHub pull request removed, renamed or retyped.
- Déjà does
- Scores each recorded change to that field in the last 30 days on eight published weights. At 0.80 or above it issues a signed attribution receipt (R1) naming the pull request and its score; from 0.60, a signed low-confidence receipt (R1-L) for you to confirm or reject.
- So you can
- Show an examiner which change the incident was tied to, as recorded at the time.
Read more · The engineLimit. One failure mode only: a removed, renamed or retyped field. Attribution reads Python, TypeScript and JavaScript source and .proto and .avsc schemas; Java, C# (.NET) and Go have no parser. The alerts that can name a field come from Sentry, Splunk On-Call and Alertmanager · Grafana.
- U2Available
Show what could not be attributed, for scored sources
- When
- An alert from Sentry, Datadog, Splunk On-Call or Alertmanager · Grafana reaches scoring and cannot be tied to a change: it names no field, no change clears the threshold, or a check stops scoring.
- Déjà does
- Issues a signed no-attribution receipt (R1-N) recording the lookback, how many pull requests it examined and the highest score, with the reason beside it.
- So you can
- Show that the period was watched, not only the incidents where a cause was found.
Read more · Receipt typesLimit. Scored sources only. Alerts from New Relic, Dynatrace, Honeycomb, AppDynamics and Splunk (alerts) are received but not scored yet, so they get no receipt, and whether PagerDuty, AWS CloudWatch, Azure Monitor, Google Cloud Monitoring, incident.io, Rootly and FireHydrant incidents reach scoring is still being checked.
- U3Available
Hand evidence to your auditor
- When
- SOC 2, NYDFS Part 500 or ISO 27001 fieldwork starts.
- Déjà does
- You open a scoped engagement that expires (90 days by default, at most 365). Your auditor opens a token link with no Déjà account, sees the receipts in scope, downloads the period report with its signed manifest and checks it with dsr-verifier-cli.
- So you can
- Hand over evidence with no screenshots and no vendor login, and have it checked on the auditor's own machine.
Read more · For auditorsLimit. The Primary Owner, an Owner, an Admin or a Compliance Lead of the vault can open an engagement, and so can a member whose custom role grants sharing with an external auditor. The period report packs R1, R1-L and R1-N receipts; other types in scope are listed in the portal, not packed. dsr-verifier-cli is in early access for customers. [Awaiting owner: public release of the verifier CLI]
For security: a vendor you can watch.
The CISO's team and third-party risk, reviewing Déjà as a vendor.
- U8Available
Evidence configuration changes
- When
- An admin rotates a signing key, changes SSO, connects a tool or opens an audit engagement.
- Déjà does
- Writes the change as a signed governance receipt (RG), chained behind your signed genesis receipt. The integrity monitor checks that chain every 15 minutes.
- So you can
- Evidence access and configuration control over Déjà from the same ledger as the incidents.
Read more · Receipt typesLimit. A governance receipt's signed bytes hold the change type, who made it and hashes of the state before and after, not the settings themselves.
- U9Available
Approve Déjà's own access to you
- When
- Déjà support needs to look at your account.
- Déjà does
- A Déjà staff member asks to read your organisation's activity for 1 to 24 hours, and only an Owner can approve, decline or end it. Every read under an access is listed, with 90 days exportable as CSV for your auditors.
- So you can
- Evidence vendor-access control for third-party risk.
Read more · Security & trustLimit. This covers reads through Déjà's staff console. It is not a statement about database access outside the console.
- U10Available
Watch Déjà from your SOC
- When
- Your security team wants Déjà's activity in the SIEM.
- Déjà does
- Your organisation's audit log is posted to an HTTPS address you choose. Each POST carries an HMAC-SHA256 Deja-Signature header, and adding, resuming or re-keying a stream is a governance receipt.
- So you can
- Monitor the vendor with the tools you already run.
Read more · Security & trustLimit. No SIEM has been tested by name: the stream goes to any HTTPS receiver you run. It is not a receipt, and it is not in the ledger.
- U11Available
Run access from your identity provider
- When
- People join and leave through your identity provider.
- Déjà does
- Your identity provider adds, updates and suspends members through SCIM 2.0, with a token Déjà issues. Removing a member stays on the Team page. Each change to the token is a governance receipt. Sign-in is SAML with Okta, Microsoft Entra ID (Azure AD), Google Workspace, OneLogin, PingIdentity or JumpCloud, or OIDC with Auth0 or Okta, or any SAML 2.0 or OIDC provider. MFA is required on every paid plan, after a 14-day enrolment grace.
- So you can
- Meet access reviews without a second user list.
Read more · Security & trustLimit. SCIM suspends a member rather than removing them; removal stays on the Team page. The setup marks PingIdentity and JumpCloud as beta.
- U12Available on Enterprise and Sovereign
Hold the signing key yourself
- When
- Policy says signing keys live in your own KMS.
- Déjà does
- A vault signs with your own AWS KMS key, RSA-PSS or ECDSA, through a cross-account role with an external ID, with scheduled rotation.
- So you can
- Hold the key that signs your evidence.
Read more · Security & trustLimit. AWS KMS only: Azure Key Vault and GCP KMS are not implemented. For vaults on their own KMS key, Déjà publishes the current public key of at most one such vault per organisation and no key that has been rotated out, so any other key an auditor needs comes from the customer.
For engineering and SRE: the record beside your tools.
The teams who connect Déjà and live with it on call.
- U6Available
Time a change by its deploy
- When
- A pull request merges hours before it deploys.
- Déjà does
- Records each production deploy against its commit, from GitHub Actions, CircleCI, Jenkins and other CI, Flux or Argo CD, and times the change from its recorded deploy rather than its merge when weighing how close it came before the incident.
- So you can
- Weigh a change by when it shipped, not when it merged.
Read more · IntegrationsLimit. Deploy anchoring, which drops a change deployed after the incident, is a Déjà deployment setting and is off by default. Without it, such a change stays a candidate, and the attribution receipt records that the gate was off. A change with no recorded deploy is timed from its merge.
- U7Available
See what else changed
- When
- A flag flips or an infrastructure run applies just before an incident.
- Déjà does
- Shows LaunchDarkly, Terraform Cloud and Spacelift changes beside the receipt.
- So you can
- Give reviewers the context beyond code.
Read more · IntegrationsLimit. Shown on a receipt when they happened in the 24 hours before its incident. They do not change what it attributes, and are not part of the signed record.
- U14Available
Read receipts into your own tooling
- When
- You want receipts in your data lake or your own dashboards.
- Déjà does
- A REST API, described in OpenAPI at /api/v1/openapi.json, reads receipts, vaults, engagements, evidence packages, frameworks, service zones and the audit log, and verifies a receipt. Keys are scoped to one vault or the organisation, expire after 30, 90, 180 or 365 days, and are rate limited.
- So you can
- Integrate the record with internal tooling.
Read more · DocsLimit. Its webhook endpoints answer 410 Gone: receipts reach your systems through a vault's webhook destination, set up in Connections. Its only other endpoints take data in, as signals and deploy events, and manage its own keys.
For compliance and GRC: evidence where you file it.
Compliance, regulatory and GRC, who file the evidence and answer for it.
- U4Beta
File receipts into your GRC tool
- When
- A receipt is issued in a vault connected to a GRC tool.
- Déjà does
- Files each attribution (R1) and no-attribution record (R1-N) as SOC 2 evidence in Vanta or Drata, or attaches each receipt as evidence to one ServiceNow GRC control or one Archer record.
- So you can
- Have the evidence land in the GRC tool without a person moving it.
Read more · IntegrationsLimit. Each is in beta: built to the vendor's documented API, and not yet validated against a live instance by us.
- U5Beta
Tie an incident to its change ticket
- When
- A pull request deploys under a ServiceNow change number that your pipeline sends with the deploy.
- Déjà does
- Reads exactly that change record from ServiceNow after the deploy, and shows it beside the receipt.
- So you can
- Tie an incident to the approved change it shipped under, for change-management testing.
Read more · IntegrationsLimit. Needs a ServiceNow connection, which is in beta, and a pipeline that sends the change number: Déjà never searches ServiceNow for one. The record is shown beside the receipt, not scored and not in its signed bytes.
- U13Available
Send the committee a recurring summary
- When
- A quarter ends, or a risk committee meets.
- Déjà does
- Sends a scheduled Quarterly Business Review, Monthly Operations Brief, Compliance Officer Brief or Annual Compliance Summary by email to members you choose and to outside addresses, each recorded with who added it and when.
- So you can
- Give the committee the same summary on a schedule, without assembling it by hand.
Read more · Talk to usLimit. A report is an emailed summary, not a receipt: it is not in the ledger and no engagement packs it. Its kept copy and link expire 90 days after it was last sent.
Not built, and not claimed.
These are asked for, and Déjà does not do them today. None of them appears above as something you can do, and none should be read into a row that does.
- U15
Resolution receipts at scale
Narrow, not claimed at scale
- What it would be
- When an incident is resolved and the fix holds or fails, a signed resolution receipt (R2), with a hashed R2-F when a gate fails and a hashed R2-R when it recurs.
- Today
- Most organisations get no resolution receipt (R2) yet: Déjà issues one only for an incident with an attribution receipt (R1), once 48 hours have passed since a user marked it resolved, and only if every gate then has a reading, which takes connected source control, Sentry, and Datadog (with a metrics read key) or New Relic.
- U16
Freeze evidence
Not built
- What it would be
- Flag a receipt issued while a deploy freeze was in effect.
- Today
- A function that checks for an active freeze exists in the code, and nothing calls it, so no receipt is flagged.
- U17
Destruction receipt
Not built
- What it would be
- When you leave: export, then destruction, then a signed receipt recording the destruction.
- Today
- Tables for retention policies and deletion events exist. Nothing in the product schedules a deletion or issues a receipt for one, and no receipt type records a destruction.
- U18
Stall alert
Not built
- What it would be
- Alert you when a connected source stops sending.
- Today
- Déjà does not yet alert you when a connected source stops sending, and in the ledger a quiet source looks the same as a quiet period. An hourly check exists, but it reads only signals posted to Déjà's own incident endpoint as Sentry or GitHub, and the Sentry and GitHub connections post none.
- U19
Cross-repository attribution
In validation, not claimed
- What it would be
- Attribute an incident in one team's service to a change in another team's repository.
- Today
- In validation. Not claimed until it is demonstrated.
If a row's limit matters to you, ask us before you rely on it.
Ask to see it on your own systems during the trial, and hold us to what you see rather than to this page.