A run targeting a protected environment pauses before its first step and waits for a person. This is how to resolve one.
Before you begin#
You need the Operator role or above. A Viewer cannot approve. If the environment is also protected, you need an explicit grant on it as well.
1. Open the approvals inbox#
Open Approvals. Every run waiting on a decision you are entitled to make is listed, with its plan, the environments it touches, and who started it.
2. Check what the run would do#
Do not approve from the plan name. Open the plan and read the steps, then dry run it if one has not already been run against these targets.
Step 2 Deploy the site config template.deploy
web-01 no change
web-02 would change /etc/nginx/sites-enabled/app.conf +4 -2That tells you which hosts the run actually touches. See dry runs for what a preview does and does not prove.
3. Check the revision#
The approval names the plan revision it was requested against. If the plan has been edited since, Opafra shows that the revision moved rather than blocking the decision.
4. Decide#
Approve, or reject. A reason is optional and is kept on the record.
On approval the run resumes from the beginning in the mode it was started in. On rejection it ends without having run anything.
Selecting several runs enables Bulk approve and Bulk reject. Use it only for runs you have actually reviewed; the record does not distinguish a bulk decision from a considered one.
Verify it worked#
The run leaves the inbox and its status changes from Paused to Running, then to Completed:
Status Completed
Approved by [email protected]
Approved at 2026-09-08 14:22
Requested revision 7
Approved revision 7Matching revision numbers confirm the plan did not move between request and decision. The
same decision appears in the audit log as approval.continue
or approval.abort, with both revision numbers recorded.
Next steps#
- Approval gates for why the gate belongs to the environment
- Audit log for what the decision records