Skip to content

Approval gates

Approval gates route high-impact project events to eligible reviewer groups. They add a decision boundary; they do not replace policy checks or authorize a different Terraform plan.

Typical time
15–30 minutes
You need
Policy-management access, a project, and an active reviewer group
Outcome
A project gate with reviewable scope, reviewers, and audit history

Open Governance → Approval Gates, select a project, and review the summary. If there are no eligible reviewer groups, select Reviewer groups and configure membership in Team & Access first.

The Minimum Approvals value cannot exceed the active eligible reviewers available through the selected Required Reviewer Groups.

Approval Gates workspace with a synthetic selected project, readiness metrics, reviewer group action, and one active rule
Approval gates 1 of 7 · Check project and reviewer-group readinessSynthetic selected project, summary metrics, reviewer-group control, and one active gate.

Select New gate and enter:

  • a clear name, trigger, and description;
  • project or workspace scope, environment, and gate mode;
  • Minimum Approvals and Required Reviewer Groups;
  • timeout and escalation behavior;
  • status plus Emergency Override and Auto-block critical findings.

Review the impact, then create the gate. Emergency override should be enabled only for a separately governed incident process.

Create Approval Gate form with synthetic production trigger, scope, environment, and enforcing mode
Approval gates 2 of 7 · Define gate scope and triggerSynthetic pre-submission form with name, trigger, scope, environment, and mode.
Create Approval Gate form showing minimum approvals, required reviewer group, timeout, escalation, and safety switches
Approval gates 3 of 7 · Set reviewer and safety controlsPre-submission gate form showing synthetic reviewer, timeout, escalation, and safety controls.

Select a table row or its View details action. Verify scope, trigger, environment, minimum approvals, timeout, reviewer groups, workflow, and status. Use Refresh after another authorized user changes the project.

Approval Gate details for a synthetic production plan review showing gate summary and reviewer group capacity
Approval gates 4 of 7 · Review one approval gateSynthetic read-only gate details showing scope, trigger, approval threshold, reviewer capacity, and workflow.

From details select Edit Gate, or use the row action. Recheck every field, especially trigger, scope, environment, reviewer groups, and minimum approvals, then save. A changed gate applies to future matching workflows; it must not be treated as retroactive approval for an existing plan.

Edit Approval Gate form with synthetic existing scope, reviewers, approvals, and save control
Approval gates 5 of 7 · Edit a gate safelySynthetic edit form before any field is changed or saved.

Open the row menu:

  • select Disable gate to stop an active gate while retaining its record;
  • select Delete gate to remove the gate configuration.

Read the confirmation and select the matching confirm action. Before either change, verify that no production apply or other protected workflow depends on the gate. Neither action erases audit history.

Disable approval gate confirmation dialog for a synthetic production plan review with cancel and disable actions
Approval gates 6 of 7 · Confirm disabling or deleting a gateSynthetic disable confirmation before the persistent action is confirmed.

Select Audit on the page or Audit History in the header. Review recent project events for approval-gate creation, updates, disabling, and deletion. Use the main Audit Logs destination for broader filtering and verified evidence readback.

Approval Gate Audit History drawer with synthetic created and updated gate events
Approval gates 7 of 7 · Review approval-gate audit eventsSynthetic recent create and update events in Approval Gate Audit History.

The selected project shows the intended active or disabled gate, reviewer capacity meets the approval threshold, and Audit History records the material change.

  • New Gate unavailable: confirm policy-management permission and select a project.
  • No reviewer groups: configure an eligible active group in Team & Access.
  • Minimum approvals rejected: lower the threshold or add active eligible reviewers.
  • Gate not triggered: confirm trigger, scope, environment, and workflow match the new event.

Source and deployment wiring alone are not proof that a live approval path blocked or released a runtime operation. Verify that behavior in an authorized environment.