Configuring and enabling command approvals

Configure command approvals to enforce an oversight process, or a peer-review process, for running restricted commands.

Before you begin

To configure and enable command approvals, you must have system privilege.

About this task

The command-approvals feature is configured on a per-server basis. To configure command approvals for all servers that are managed by the Operations Center, you must complete the following procedure on each server.

When the command-approvals feature is enabled, administrators who are not approvers can issue restricted commands, but the commands do not run unless they are approved. In this way, the command approvals feature enforces an oversight process, which can help prevent an administrator from running a command that might have unintended consequences.

You configure command approvals by designating the approval administrators and by specifying whether approval administrators are exempt from command approvals. An approval administrator can approve or reject pending commands. If approval administrators are exempt from command approvals, restricted commands that are issued by approval administrators can run unimpeded. Specifying that approval administrators are not exempt enforces a peer-review process for all administrators.

Any number of administrators can be designated as approval administrators. You should designate enough approval administrators so that pending commands can be approved or rejected in a timely manner. Pending commands that are not approved within 72 hours are automatically rejected.

An approval administrator's privilege classes are irrelevant. The administrator who issues a restricted command must be authorized to run the command, but the approval administrator does not require the same level of authorization.
Tip: To monitor when configuration changes are made to the command-approvals feature, you can define an alert trigger for the informational message ANR2744I. The server issues this message when approval administrators are added or removed, when approval administrators are made exempt or nonexempt, and when the command-approvals feature is enabled or disabled.
Remember: The command-approvals feature is not a security mechanism. To prevent administrators from accessing commands that are outside their job responsibilities, assign them only to the privilege classes that they require.

Procedure

To configure and enable command approvals on a server, complete the following steps:

  1. On the Operations Center menu bar, click Servers.
  2. On the Servers page, select a server.
  3. Click Details and then click the Command Approvals tab.
  4. Designate one or more approval administrators. For each administrator to be designated, click + Approver.
  5. Specify whether approval administrators are exempt from command approvals. If approval administrators are exempt from command approvals, they and can run restricted commands unimpeded. To change the setting, click the edit icon () for the Approvers Exempt field.
  6. To enable command approvals, click the edit icon () for the Status field.