Four-eyes approval
CommunityTeamPro
Some actions should not rest on one person: a discard cannot be undone, a replay to production can trigger payments twice. With four-eyes approval they wait for a second operator.

Turn it on
WARREN_APPROVAL_ACTIONS=REPLAY,DISCARD,PURGE # or a part of it
WARREN_APPROVAL_EXPIRES_AFTER=24h
How it works
- An operator asks for the action as usual. Warren checks it as if it ran (queue, target, delivery limit, rate) and stores it under Approvals with a one-line summary; nothing changes in the queue. The API answers
202with the request. - Another operator opens it, sees exactly what was asked, and approves or rejects it with a reason. Nobody approves their own request.
- Approved, it runs exactly as asked, in the requester's name, with the approver next to it in the audit log (
approvedBy). - The requester can withdraw it; nobody decided after
WARREN_APPROVAL_EXPIRES_AFTER, it expires.
A bulk selection is frozen by its dry run before it is stored, so the approver confirms the messages the requester saw, not a new reading of the queue. A purge removes what is in the queue when it is approved. Replay rules are not affected: an admin sets them up to run without anyone at hand.