Configuring and enabling command approvals
Configure command approvals to enforce an oversight process, or a peer-review process, for running restricted commands.
Before you begin
To configure and enable command approvals, you must have system privilege.
About this task
The command-approvals feature is configured on a per-server basis. To configure command approvals for all servers that are managed by the Operations Center, you must complete the following procedure on each server.
When the command-approvals feature is enabled, administrators who are not approvers can issue restricted commands, but the commands do not run unless they are approved. In this way, the command approvals feature enforces an oversight process, which can help prevent an administrator from running a command that might have unintended consequences.
You configure command approvals by designating the approval administrators and by specifying whether approval administrators are exempt from command approvals. An approval administrator can approve or reject pending commands. If approval administrators are exempt from command approvals, restricted commands that are issued by approval administrators can run unimpeded. Specifying that approval administrators are not exempt enforces a peer-review process for all administrators.
Any number of administrators can be designated as approval administrators. You should designate enough approval administrators so that pending commands can be approved or rejected in a timely manner. Pending commands that are not approved within 72 hours are automatically rejected.
Procedure
To configure and enable command approvals on a server, complete the following steps:
) for the