Managing command approvals
Certain commands present heightened risks for unintentional data loss and other unwanted consequences. You can subject these commands to oversight by requiring command approvals. When you enable the command-approvals feature, you restrict administrators from running these commands until the commands are approved by another administrator.
About this task
When the command-approvals feature is enabled, administrators can issue the restricted commands, but the commands do not immediately run. Instead, the commands are held, pending approval. To use the command-approvals feature, you must designate one or more administrators as approval administrators who can approve or reject the restricted commands.
The command-approvals feature is not a security mechanism. It is a safeguard for establishing an oversight or peer-review process for restricted commands, and relies on the cooperation of all participants. Privilege classes remain the security mechanism by which you grant individual administrators access to some or all commands.
- Making a policy set the active policy set by using the ACTIVATE POLICYSET command can result in accidental data loss or failure to back up client data. If the new policy set deleted a management class, some backup files might rebind to the default management class, which might retain fewer backup versions. If the new policy deletes a copy group, files that are bound to the management class might not be backed up.
- The DEACTIVATE DATA, DECOMMISSION NODE, and DECOMMISSION VM commands cannot be reversed. You cannot reactivate data or recommission clients or virtual machines. In all three situations, data is eventually deleted according to policy specifications.
- The RELEASE RETSET command releases a retention set from a retention hold. When a retention set is released from the hold, and if the retention set is not in another hold, the retention set reverts to being retained according to its own expiration date. If the retention set is past its expiration date, it is deleted the next time expiration processing runs.
The Operations Center issues commands in the background
based on user actions. If command approvals are enabled, and the Operations Center issues a restricted command on behalf of an
administrator, the command is held, pending approval. The Operations Center is updated to show the requested change, but the
server is not updated. A pending-approval icon (
) is displayed by the requested change to show that the server is not updated.
By using the Operations Center, an approval administrator can view all the commands that are pending approvals for a server. For each pending command, the approval administrator can view the full command that was issued, and information such as the administrator who issued the command and when the command was issued. The approval administrator can then approve or reject the command. If the command is approved, it runs on the server and the command output is displayed. If the approval administrator rejects the command, the approval administrator can specify a reason why the command was rejected.
The administrator who issued a restricted command can view the list of pending commands and the history of command approvals. By viewing the history, the administrator can determine which commands were approved and which were rejected. If a command was rejected, the administrator can view the reason why it was rejected. If an administrator issued a command that is still pending, and the administrator does not want the command to run, the administrator can withdraw the command.
Procedure
Command approvals are configured and tracked on each server individually. To access command approvals for a server, complete the following steps: