All guides

Put an Approval Step in Front of Risky Changes

See which gateway changes ask for approval, review them in the Approval queue, and choose when an admin may apply a change immediately.

9 min read Updated October 2026LLM FinOps
On this page
  1. 01What you'll set up
  2. 02Which changes ask for approval
  3. 03How an approval works
  4. 04Open the Approval queue
  5. 05Approve or reject
  6. 06Who can approve
  7. 07Apply immediately
  8. 08Everything is recorded
  9. 09What a reviewer checks
  10. 10Approvals and code
  11. 11Set a team routine
  12. 12If something goes wrong

01

What you'll set up

Some changes to your AI gateway deserve a second look: raising a budget, allowing a costlier model, switching on a risky cache. In about nine minutes you will learn which changes ask for approval, review one in the Approval queue, and decide when a change may skip the wait.

  • A clear list of the changes that ask for approval
  • A review in the Approval queue, with a reason
  • A choice about applying changes immediately
  • A record of every request and decision

Owners and admins review approvals.

02

Which changes ask for approval

Approvals guard the changes that can raise cost or risk. Tightening something never needs one.

Approval typeAsked when you
Budget limit changeRaise a daily or monthly budget on an existing policy
High-risk model enablementAllow models a policy did not allow before
MCP tool server registrationActivate a new tool server
Semantic cache enforceSwitch the semantic cache to Enforce
Route changeChange how adaptive routing sends traffic
Model downgradeMove a policy to a cheaper model
Prompt production deploymentRelease a prompt version to production
Heavy guardrail enforcementApply a recommended guardrail change

03

How an approval works

A change that needs approval is saved as a request. It takes effect when a reviewer approves it.

From request to live
  1. 1Change requested

    In the console, the API, or Terraform

  2. 2Request waits

    In the Approval queue

  3. 3Reviewer decides

    Approve or reject, with a reason

  4. 4Change applied

    Approval makes it live at once

Rejecting leaves things as they were. Both decisions are recorded.

04

Open the Approval queue

The queue is on the Audit tab.

  1. 1

    Open AI → Audit

    The Approval queue is the first card.

  2. 2

    Read the badge

    It shows how many requests are pending.

  3. 3

    Switch the filter

    Pending shows what needs a decision. Approved shows past decisions.

  4. 4

    Read a request

    Each shows its type, what is changing, who asked, and which role may approve it.

AI → Audit → Approval queue

2Approval queue · 1 pending

3Filter
PendingApproved

4Budget limit change · pending

What changesMonthly budget $2,000 → $5,000
Requested bymaya · Oct 5, 2026
Requiresadmin
Policysupport-app-production
Cost impact$3,000.00
Appssupport-assistant
Reason
Reason (optional for approve, recommended for reject)
RejectApprove
Pending requests, with a reason box and Approve and Reject.

05

Approve or reject

Review the change, add a note, and decide.

  1. 1

    Read what changes

    Budget changes show the before and after. Policy changes show the fields that differ.

  2. 2

    Add a reason

    Optional for an approval, recommended for a rejection.

  3. 3

    Choose Approve or Reject

    Confirm the prompt. Approving takes effect immediately.

06

Who can approve

Every approval type needs an owner or admin to review it.

RoleCan requestCan approve
Owner, adminYesYes, including their own requests
Other rolesWhere they may editNo

A requester below admin can never clear their own request, so the person who asks is not the person who approves. Owners and admins already hold full authority, so they may approve what they request.

07

Apply immediately

When you are an owner or admin and you do not need a second reviewer, you can approve your own change as you save it.

  1. 1

    Open the policy form

    Go to the Review step.

  2. 2

    Switch on Apply immediately

    It skips the Approval queue for changes you may approve yourself.

  3. 3

    Save

    The request is created and approved in one step, with a note that it was self-approved.

Apply immediately does not hide anything. The request and the self-approval are still recorded in the audit log.

08

Everything is recorded

Each request and each decision lands in the Control Plane Audit Log.

EventWhat it records
approval.requestWho asked, what for, and when
approval.approveWho approved, when, and their note
approval.rejectWho rejected, when, and their note

The guide on reading the audit log shows how to search them.

09

What a reviewer checks

A good review takes a minute when you know what to look at.

TypeLook atAsk
Budget limit changeThe before and after valuesIs the new limit funded, and is it temporary?
High-risk model enablementThe models being addedDo these models fit our data and cost rules?
MCP tool server registrationThe server name, URL, and tool rulesDo we know and trust this server?
Semantic cache enforceThe mode and thresholdsHave we read real matches in Observe?
Route changeThe candidates and the shareHas it run in Observe?
FieldBeforeAfter
Daily budget$150$400
Monthly budget$3,000$8,000
Requested bya team lead
Example, for illustration

10

Approvals and code

Changes made through the API or Terraform follow the same rules as changes made in the console.

  • A change that needs approval is saved as a request, and the apply reports that it is pending
  • Tool servers accept apply_immediately in Terraform, which approves in the same apply when your role allows it
  • A pending request shows in the Approval queue exactly as a console request does

That keeps one standard for every path into your gateway.

11

Set a team routine

A short habit keeps the queue from backing up.

  • Pick one or two reviewers and name them in your runbook
  • Check the Pending badge each morning
  • Reject with a reason, so the requester knows what to change
  • Use Apply immediately only for changes you would have approved anyway

12

If something goes wrong

Most questions are about waiting changes.

What you seeLikely causeFix
A budget change did not take effectIt is waiting in the Approval queueApprove it, or save again with Apply immediately
A tool server shows Pending approvalActivation needs a reviewApprove it in the queue
Approve is missingYour role cannot review approvalsAsk an owner or admin
You cannot approve your own requestYour role is below adminAsk another reviewer

Put This Guide Into Practice

Cloptima automates the strategies described in this guide.

No credit card required
5-minute setup
Free trial