All Products
Search
Document Center

Bastionhost:Command Approval

Last Updated:Jun 20, 2026

When an O&M engineer attempts to run a command subject to a control policy requiring Command Approval, an administrator receives an approval request in the Bastionhost console. The command can run only after it is approved. If rejected, the command is blocked. This topic describes how to approve or reject these command requests.

Prerequisites

A control policy requiring Command Approval is configured, and an O&M engineer has attempted to run a command subject to this policy. To configure a control policy, see Configure a control policy.

On the Create Control Policy page, click Settings next to Command Approval to configure the feature.

Approve commands

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Approval > To-do List.

  4. On the Command Approval tab, find the request that you want to review and, in the Actions column, click Allow or Reject.

Command approval history

  1. Log on to the Bastionhost console. In the top navigation bar, select the region where your Bastionhost instance is located.

  2. In the list of Bastionhost instances, find the target instance and click Manage.

  3. In the navigation pane on the left, choose Approval > Handled Items.

  4. The command approval history is displayed on the Command Approval tab.