Skip to content

    Approve a gated run

    Resolve a run waiting at an approval gate, after checking what it would do and which plan revision you are approving.

    A run targeting a protected environment pauses before its first step and waits for a person. This is how to resolve one.

    Before you begin#

    You need the Operator role or above. A Viewer cannot approve. If the environment is also protected, you need an explicit grant on it as well.

    1. Open the approvals inbox#

    Open Approvals. Every run waiting on a decision you are entitled to make is listed, with its plan, the environments it touches, and who started it.

    2. Check what the run would do#

    Do not approve from the plan name. Open the plan and read the steps, then dry run it if one has not already been run against these targets.

    dry run, before approving
    Step 2  Deploy the site config    template.deploy
      web-01   no change
      web-02   would change   /etc/nginx/sites-enabled/app.conf   +4 -2

    That tells you which hosts the run actually touches. See dry runs for what a preview does and does not prove.

    3. Check the revision#

    The approval names the plan revision it was requested against. If the plan has been edited since, Opafra shows that the revision moved rather than blocking the decision.

    4. Decide#

    Approve, or reject. A reason is optional and is kept on the record.

    On approval the run resumes from the beginning in the mode it was started in. On rejection it ends without having run anything.

    Selecting several runs enables Bulk approve and Bulk reject. Use it only for runs you have actually reviewed; the record does not distinguish a bulk decision from a considered one.

    Verify it worked#

    The run leaves the inbox and its status changes from Paused to Running, then to Completed:

    run record
    Status              Completed
    Approved by         [email protected]
    Approved at         2026-09-08 14:22
    Requested revision  7
    Approved revision   7

    Matching revision numbers confirm the plan did not move between request and decision. The same decision appears in the audit log as approval.continue or approval.abort, with both revision numbers recorded.

    Next steps#