Feature

Approval Workflows

Route risky infrastructure changes through informed review—showing diffs, policy signals, and decision context.

Approval workflows make governance usable.

Without an approval workflow, infrastructure teams rely on ad-hoc practices: “someone will review this,” “we trust the pipeline,” or “we’ll fix it later.”

OrchesTerra’s approval workflows are designed so that review happens with the right context.

What reviewers see

An informed review includes:

  • the infrastructure diff (what changes and where),
  • governance/policy evaluation results,
  • expected impact and risk classification,
  • and the decision reason recorded for audit.

How approvals connect to reconciliation

Risky remediation—especially drift fixes—should not be executed without review.

OrchesTerra ties approvals to governed reconciliation so the executed apply corresponds to the reviewed plan context.

FAQ

What changes should require approval?

Typically network perimeter changes, IAM trust and permission updates, managed database configuration changes, and any change that increases external exposure.

Platform evaluation

See OrchesTerra on your infrastructure

Request access to generate architecture from a repository, review the plan, and run governed reconciliation across AWS, Azure, GCP, and OCI.