Skip to main content

Approvals

Approvals ensure that high‑risk changes are reviewed by the right people and that an audit trail exists for regulators, customers, and internal governance.

In Cloudaware, approvals are commonly implemented using Salesforce Approval Processes (or equivalent automation), with outcomes visible on the CI’s CHANGE MANAGEMENT tab as Approval History.

What to Approve

Approve based on change patterns, not just on “any update”:

  • Changes in production environments or critical applications
  • Access control changes (IAM roles/policies, key grants, group membership)
  • Public exposure changes (security groups/ACLs, bucket policies)
  • Baseline or policy control changes (exceptions, allow‑lists)

Routing and Policy

Use CMDB context to route approvals:

  • Application or service owner
  • Environment (prod vs non‑prod)
  • Account/subscription/OU
  • Risk band (low/medium/high)

Typical Approval Flow

  1. A CI change event or a planned change request meets entry criteria.
  2. The record is submitted for approval (manually or automatically).
  3. Approvers receive notifications (email/Slack/ITSM).
  4. Outcome is recorded as Pending/Approved/Rejected and stored in Approval History.
  5. Automation proceeds based on the decision (for example, proceed, block promotion, or open an incident/change ticket).

Prepackaged Approval Processes

Many Cloudaware accounts include example approval processes for common governance scenarios. Treat them as starting points: review, tailor entry criteria and queues, then activate where they make sense.

Delegation and Escalations

To keep approvals from becoming a bottleneck:

  • Use delegation for approvers who are out of office.
  • Add escalation paths (time‑based reminders, on‑call routing).
  • Auto‑approve standard changes that are tightly scoped and well‑tested.