DNSMentor

Changes & approvals

How approvals work

1 min read · 2 related

How do I set up approval rules for DNS changes?

Approval policy is set in Admin → Settings and can be configured per organisation and per engineer. A senior who has demonstrated the skill can apply unsupervised while somebody in their first week cannot, which is what stops teams switching approvals off entirely.

# Why per engineer matters

One approval setting for everybody is the reason most approval workflows get disabled within a month. Either it is loose enough to be pointless or tight enough to be unbearable. DNSMentor sets a baseline for the organisation and then adjusts by engineer, so ceremony lands where the risk is.

# What you can vary

  • Whether approval is required at all, per organisation.
  • Per engineer, based on demonstrated skill level.
  • By record type — an MX cutover is not a vendor verification TXT.
  • By client, for the ones with governance requirements in their contract.

# Separation of duties

An engineer cannot approve their own change. This is not configurable, because an audit trail in which the author is also the approver evidences nothing.

Was this helpful?

Related

Still stuck?

Raise a ticket from inside the platform and your tenant, plan and recent activity come attached automatically. A client currently offline is treated as urgent on every plan.

Last updated