Overview
Step-up authorization pauses action execution until a human approves. Use it for:- Destructive operations (delete, drop)
- High-value transactions
- External data transfers
- Privilege escalation
Basic Flow
Implementation
Approval Service
Slack Integration
Policy Configuration
Best Practices
Keep context visible
Keep context visible
Show approvers everything they need: the action, parameters, user, session history, and why approval is required.
Set appropriate timeouts
Set appropriate timeouts
Too short → legitimate actions timeout. Too long → blocks workflows. Start with 1 hour, adjust based on data.
Default to DENY on timeout
Default to DENY on timeout
Fail-closed is safer. If approvers don’t respond, the action shouldn’t execute.
Support escalation
Support escalation
If primary approvers don’t respond, escalate to backup approvers before timeout.
Prevent approval fatigue
Prevent approval fatigue
Too many approval requests → rubber-stamping. Reserve STEP_UP for genuinely high-risk actions.