On this page
01
What you'll set up
Some changes to your AI gateway deserve a second look: raising a budget, allowing a costlier model, switching on a risky cache. In about nine minutes you will learn which changes ask for approval, review one in the Approval queue, and decide when a change may skip the wait.
- A clear list of the changes that ask for approval
- A review in the Approval queue, with a reason
- A choice about applying changes immediately
- A record of every request and decision
Owners and admins review approvals.
02
Which changes ask for approval
Approvals guard the changes that can raise cost or risk. Tightening something never needs one.
| Approval type | Asked when you |
|---|---|
| Budget limit change | Raise a daily or monthly budget on an existing policy |
| High-risk model enablement | Allow models a policy did not allow before |
| MCP tool server registration | Activate a new tool server |
| Semantic cache enforce | Switch the semantic cache to Enforce |
| Route change | Change how adaptive routing sends traffic |
| Model downgrade | Move a policy to a cheaper model |
| Prompt production deployment | Release a prompt version to production |
| Heavy guardrail enforcement | Apply a recommended guardrail change |
03
How an approval works
A change that needs approval is saved as a request. It takes effect when a reviewer approves it.
1Change requested
In the console, the API, or Terraform
2Request waits
In the Approval queue
3Reviewer decides
Approve or reject, with a reason
4Change applied
Approval makes it live at once
Rejecting leaves things as they were. Both decisions are recorded.
04
Open the Approval queue
The queue is on the Audit tab.
- 1
Open AI → Audit
The Approval queue is the first card.
- 2
Read the badge
It shows how many requests are pending.
- 3
Switch the filter
Pending shows what needs a decision. Approved shows past decisions.
- 4
Read a request
Each shows its type, what is changing, who asked, and which role may approve it.
2Approval queue · 1 pending
- 3Filter
- PendingApproved
4Budget limit change · pending
| What changes | Monthly budget $2,000 → $5,000 |
| Requested by | maya · Oct 5, 2026 |
| Requires | admin |
| Policy | support-app-production |
| Cost impact | $3,000.00 |
| Apps | support-assistant |
- Reason
- Reason (optional for approve, recommended for reject)
05
Approve or reject
Review the change, add a note, and decide.
- 1
Read what changes
Budget changes show the before and after. Policy changes show the fields that differ.
- 2
Add a reason
Optional for an approval, recommended for a rejection.
- 3
Choose Approve or Reject
Confirm the prompt. Approving takes effect immediately.
06
Who can approve
Every approval type needs an owner or admin to review it.
| Role | Can request | Can approve |
|---|---|---|
| Owner, admin | Yes | Yes, including their own requests |
| Other roles | Where they may edit | No |
A requester below admin can never clear their own request, so the person who asks is not the person who approves. Owners and admins already hold full authority, so they may approve what they request.
07
Apply immediately
When you are an owner or admin and you do not need a second reviewer, you can approve your own change as you save it.
- 1
Open the policy form
Go to the Review step.
- 2
Switch on Apply immediately
It skips the Approval queue for changes you may approve yourself.
- 3
Save
The request is created and approved in one step, with a note that it was self-approved.
Apply immediately does not hide anything. The request and the self-approval are still recorded in the audit log.
08
Everything is recorded
Each request and each decision lands in the Control Plane Audit Log.
| Event | What it records |
|---|---|
| approval.request | Who asked, what for, and when |
| approval.approve | Who approved, when, and their note |
| approval.reject | Who rejected, when, and their note |
The guide on reading the audit log shows how to search them.
09
What a reviewer checks
A good review takes a minute when you know what to look at.
| Type | Look at | Ask |
|---|---|---|
| Budget limit change | The before and after values | Is the new limit funded, and is it temporary? |
| High-risk model enablement | The models being added | Do these models fit our data and cost rules? |
| MCP tool server registration | The server name, URL, and tool rules | Do we know and trust this server? |
| Semantic cache enforce | The mode and thresholds | Have we read real matches in Observe? |
| Route change | The candidates and the share | Has it run in Observe? |
| Field | Before | After |
|---|---|---|
| Daily budget | $150 | $400 |
| Monthly budget | $3,000 | $8,000 |
| Requested by | a team lead |
10
Approvals and code
Changes made through the API or Terraform follow the same rules as changes made in the console.
- A change that needs approval is saved as a request, and the apply reports that it is pending
- Tool servers accept apply_immediately in Terraform, which approves in the same apply when your role allows it
- A pending request shows in the Approval queue exactly as a console request does
That keeps one standard for every path into your gateway.
11
Set a team routine
A short habit keeps the queue from backing up.
- Pick one or two reviewers and name them in your runbook
- Check the Pending badge each morning
- Reject with a reason, so the requester knows what to change
- Use Apply immediately only for changes you would have approved anyway
12
If something goes wrong
Most questions are about waiting changes.
| What you see | Likely cause | Fix |
|---|---|---|
| A budget change did not take effect | It is waiting in the Approval queue | Approve it, or save again with Apply immediately |
| A tool server shows Pending approval | Activation needs a review | Approve it in the queue |
| Approve is missing | Your role cannot review approvals | Ask an owner or admin |
| You cannot approve your own request | Your role is below admin | Ask another reviewer |