Allow Commit Approvals Without Requiring Root Admin Role
We’ve set up automations to manage module updates at the root level, which helped reduce the number of people who need admin access to the root space. However, one issue remains:
Right now, confirming a run before plan/apply (the "commit approval") requires root-level admin privileges. We’d prefer if this approval could be handled with a separate scoped permission or role, so we don’t need anyone to have persistent admin access.
This would help us better align with least privilege access and compliance requirements and reduce audit complexity.
Ideally, it would work similarly to how we assign access to specific spaces or stacks today, without needing full admin rights at the root.
Log in to comment and vote
Comments2
Sep 17
PinnedWe believe this should be already possible in the product. No Root Admin role is needed to approve. Please connect with our Support team if this is still an issue.
Black Breeze
Sep 3, 2025
I’m not sure about your specific setup but the product should not require root admin privileges for things like run approvals. I’m routing this to our Solutions Engineering. They will be in touch with you to discuss the setup and your options.