Warren
Team and compliance

Four-eyes approval

CommunityTeamPro

Some actions should not rest on one person: a discard cannot be undone, a replay to production can trigger payments twice. With four-eyes approval they wait for a second operator.

A discard of three messages waiting for approval, with the requester's reason
A discard of three messages waiting for approval, with the requester's reason

Turn it on

WARREN_APPROVAL_ACTIONS=REPLAY,DISCARD,PURGE   # or a part of it
WARREN_APPROVAL_EXPIRES_AFTER=24h

How it works

  1. An operator asks for the action as usual. Warren checks it as if it ran (queue, target, delivery limit, rate) and stores it under Approvals with a one-line summary; nothing changes in the queue. The API answers 202 with the request.
  2. Another operator opens it, sees exactly what was asked, and approves or rejects it with a reason. Nobody approves their own request.
  3. Approved, it runs exactly as asked, in the requester's name, with the approver next to it in the audit log (approvedBy).
  4. The requester can withdraw it; nobody decided after WARREN_APPROVAL_EXPIRES_AFTER, it expires.

A bulk selection is frozen by its dry run before it is stored, so the approver confirms the messages the requester saw, not a new reading of the queue. A purge removes what is in the queue when it is approved. Replay rules are not affected: an admin sets them up to run without anyone at hand.