Docs / Knowledge Base / Change Control: risk levels and approval
Change Control: risk levels and approval
Change Control
Every change request has a risk level (LOW / MEDIUM / HIGH) which determines whether it needs approval before it can be implemented:
- LOW — no approval required. Goes straight to DRAFT, and can be marked implemented once you're ready.
- MEDIUM or HIGH — requires approval before implementation. The change sits in PENDING_APPROVAL until someone signs off.
Internal vs client approval
You choose who approves at creation time:
- Internal approval — any other staff member (not the creator — you can't approve your own change request) approves inside the platform.
- Client approval — the client's own contact gets emailed a secure, time-limited link (no Graften login needed) to approve or reject directly. This is the same secure-link pattern used for Service Desk quote approvals — a random, single-use, hashed token, never a shared password or generic link.
Linking a specific asset
A change request can optionally reference a specific asset it affects — useful for showing "this change touches 3 critical, internet-facing servers" at a glance, rather than relying on the free-text category field alone.
Open in the interactive docs