Skip to main content

Access Reviews And Approvals

Access reviews verify whether existing authority is still needed. Approval workflows add a second authorized person before selected production or destructive operations execute.

Run An Access Review

Completed organization access review

  1. Open Organization -> Reviews.
  2. Select New review.
  3. Name the campaign.
  4. Choose an organization, group, workspace, guest population, or workload scope.
  5. Assign one accountable reviewer.
  6. Set a due date.
  7. Create the campaign.

The assigned reviewer inspects each grant and chooses Retain or Revoke with a reason. Revocation takes effect immediately and can be retried safely without applying twice.

Use Protected-Action Approvals

Organization approval queue

When production or destructive approval policy is enabled:

  1. An authorized requester starts the protected operation.
  2. Moltern creates a request bound to the exact action, resource, resource version, organization, requester, and expiry.
  3. A different authorized person reviews it in Organization -> Approvals.
  4. The reviewer approves or rejects with a reason.
  5. Moltern revalidates both people and the target before execution.

A requester cannot approve their own request. Approval for one action cannot be reused for another resource or after expiry.

Approval States

StateMeaning
PendingWaiting for an eligible reviewer.
ApprovedReviewer allowed execution; the operation may still be processing.
RejectedReviewer denied the request.
CancelledRequester or authorized administrator cancelled it.
ExecutedThe bound operation completed.
FailedRevalidation or execution failed; the request is not reusable.
ExpiredThe decision window ended.

Expected Result

Review outcomes update effective access immediately. Protected actions execute only after an independent, currently authorized decision and are recorded in audit history.

Troubleshooting

SymptomWhat to check
Reviewer cannot open a campaignConfirm they are the assigned reviewer and still have review permission.
Approval is unavailableConfirm the relevant policy is enabled and another eligible approver exists.
Approved action failedThe target or authority may have changed after the request was created; create a new request after correcting it.
Decision is rejected as duplicateThe item or request has already reached a final state.

Next: Manage budgets and cost centers.