Policy review

更新时间:
复制 MD 格式

Policy review is required before a policy becomes active. To mitigate operational risks, some policy changes must be reviewed and approved before they can take effect. This topic describes how to use the policy review feature.

Overview

Note

Because the policy review feature requires coordination between multiple sub-accounts, it is disabled by default for efficiency. To enable it, contact Risk Identification support.

When the policy review feature is enabled, any change to a policy's runtime status in policy management, such as starting a trial run, automatically triggers a review process. The status change takes effect only after an approver completes the review. Currently, the approver must be a different sub-account under the same UID and cannot be the policy editor.

Trigger a review

With the policy review feature enabled, any change to a policy's status automatically triggers a review. The policy editor must select an approver to complete the policy change workflow. The approver drop-down list automatically populates with all sub-accounts under the current Alibaba Cloud account.

The Apply for Trial Run dialog box displays read-only information such as Policy ID, Policy Name, and Business Action. You can enter Remarks (up to 200 characters) and then click Save.

Perform a review

The selected policy approver can see the pending policy change request in the policy review menu. After clicking the review button, they can take action on this policy change.

The review page also displays the operation records for the current policy change and the approval history.

In the Review Action section, the approver selects a Review Result (such as Approve), enters Review Comments (up to 500 characters), and then clicks OK to submit the decision.