Currently we have a workflow issue in which a help desk technician will make a change to a policy in a tenant, and before they can communicate with an engineer to accept the drift, Nerdio has already reverted their changes.
We would like to have a workflow in which our technicians can request policy drift approval from an engineer. This process would:
- Temporarily accept drift on the policy (let's say for 24 hours)
- Send a request to the appointed approvers who can choose to either:
- Reject & revert the drift, or
- Accept the drift (either permanently or for an extended period of time)
We do not want all of our technicians to have the ability to accept drifts permanently. That would destroy our ability to manage & enforce our standards properly at scale. However, there is a real-world need for our technicians to be able to make policy changes on the fly to put out fires. We just want the ability for an engineer to review those changes in post and determine whether or not they're acceptable long term.
Comments (2 comments)