Skip to content
YAADMIN
Download

YAADMIN DOCUMENTATION

Approvals

Review and authorize an exact, fingerprint-bound execution.

VerifiedSource snapshot · 2026-10-02

Request to execution#

  1. Bound request
  2. Preview
  3. Approve or reject
  4. RBAC recheck
  5. Execute once

The approval store binds a request fingerprint to requester, interface and session. A changed request requires a new approval; consumed authorization cannot be replayed.

States and expiry#

The exact states are PENDING, APPROVED, REJECTED, CANCELLED, EXPIRED and CONSUMED. The runtime's default approval lifetime is 900 seconds.

Preview#

Cards include module/tool, risk, target and timing. Inline PowerShell previews show the bound source. Library previews fetch the bound script ID through action1.get_script, subject to read permission and provider availability. Sensitive parameters are masked by key; a universal external command/script preview protocol is not verified.

Approve and reject#

Web decisions apply to the session-owned pending request. Approve executes the bound action after current RBAC checks; reject records the decision without executing. Preview does not execute or modify the request.

Self-approval#

The default is allow_self_approval=True. A user can approve their own session card. No separate approvals.approve permission, dedicated approver role or multi-person approval chain is verified. If self-approval is disabled, the requester cannot be the approver; this alone does not implement an approver-role workflow.

Routine and critical scripts#

For inline Action1 PowerShell, the handler constructs CHANGE requests: impact=routine uses NEVER, while impact=critical uses POLICY. Library scripts use CHANGE/POLICY. Runtime RBAC can still deny or require approval. The impact input is a semantic caller/model choice, not a verified keyword safety classifier.

Storage limitation#

Action1 batch approval#

The web validates the exact same script-batch group before side effects. Groups contain 2..100 cards and execute with a concurrency cap of min(requested concurrency, number of IDs, 50). Each endpoint retains its own bound action and result.

Implementation reference: 2026-10-02. Labels distinguish verified behavior, partial implementation and architectural intent.

Search documentation

Search stays in your browser.