Skip to content

Review a Terraform plan

A Terraform plan is a change proposal for one saved revision. Review its technical impact and all attached governance evidence before requesting approval.

Typical time
10–30 minutes
You need
A successful Plan run
Next step
Run guardrails review

Open the plan from Run Library and confirm:

  • project, workspace, environment, actor, and run type;
  • latest saved revision;
  • cloud account and provider region;
  • plan creation time and Terraform version; and
  • plan availability.

An Out of date, Expired, Failed, or Unavailable plan cannot be treated as ready for apply.

Synthetic Terraform plan metadata showing workspace, environment, provider context, and safe plan details.
Plan 1 of 6 · Confirm plan identity and freshnessShow synthetic plan metadata with safe workspace and provider context.

Read Total, Create, Update, Replace, and Delete. Replacement and deletion deserve explicit review even when the total count is small.

Synthetic Terraform plan summary showing create, update, replace, delete, and total change counts.
Plan 2 of 6 · Review planned change countsShow a small synthetic plan with create, update, replace, and delete counts.

Use Search resources, All actions, and All resources filters. Open each material entry and confirm:

  • Terraform address and source file;
  • create, update, replace, delete, read, or no-op action;
  • canvas mapping and dependencies;
  • security, IAM, network, public-access, encryption, and data impact; and
  • whether the resource belongs in this workspace.

Unmapped does not automatically mean invalid, but it must be understood.

Synthetic Terraform run map showing mapped and unmapped resource entries with generic labels.
Plan 3 of 6 · Inspect mapped and unmapped resourcesShow plan filters and synthetic resource rows without raw attribute values.

Open Policy Scan Result and review:

  • scanner status;
  • whether OPA is required and whether it ran;
  • blocking and warning counts; and
  • each finding and remediation.

OPA Skipped is not displayed as a passed scan. Resolve blocking findings or use the bounded exception workflow only when the finding is eligible.

Synthetic policy finding with warning status, review guidance, and a remediation note.
Plan 4 of 6 · Review policy scanner evidenceShow a synthetic warning finding with review guidance and a remediation note.

Open the cost review and check:

  • Current monthly, After apply, Monthly change, and Annualized after;
  • usage profile and assumptions;
  • pricing catalogue, effective date, and validity;
  • trust level and trust reasons;
  • unsupported or unknown cost impact; and
  • cost policy findings or acknowledgements.

Known totals exclude unknown impact. A fallback or low-confidence estimate is not equivalent to a complete price.

Synthetic plan cost advisory reminding reviewers of an unknown-impact estimate.
Plan 5 of 6 · Review plan-linked cost evidenceShow a synthetic advisory that highlights an unknown-impact estimate for review.

Choose Run guardrails review only when the plan is ready. Page load does not create a review or notify reviewers. After creation, review risk, policy contract, approval gates, reviewer availability, cost acknowledgements, comments, and expiry.

Synthetic review-pending status showing approval progress and a pending independent-review gate.
Plan 6 of 6 · Request review for the exact planShow a synthetic Review pending state with approval progress; no review request was submitted for this capture.

The plan is ready for approval only when it is current and successful, all material changes are understood, required policy and cost evidence is present, blocking findings are resolved or validly excepted, and the review can identify eligible independent reviewers.

Save the intended revision and run Plan again. Do not approve or apply an older plan.

Treat Skipped, failed, or unavailable scanner evidence as unresolved when OPA is required.

Review every unknown or unsupported cost resource. Follow the configured cost governance effect; do not replace unknown values with zero.

Add active members to the assigned reviewer groups or project reviewer role, then refresh the review.