Updated on 2026-06-23 GMT+08:00

Configuring a Script Review Policy

In the internal development process of an enterprise, script creation or modification must be reviewed rigorously to ensure code quality and security. However, in actual operations, due to the lack of an effective review mechanism, scripts are directly released without being approved. This increases system risks. To address this challenge, you can forcibly specify a shift or an individual as the reviewer when creating or modifying a script. Reviewers can be notified by SMS messages or DingTalk. Scripts can only be created or modified once they are approved, enhancing code quality and strengthening system security.

Precautions

To configure a reviewer by specifying a shift, you need to create a shift in Overview in advance.

If manual review is enabled, you can select a risk level for scripts. If you select the same risk level when creating a custom script, this script needs to be reviewed, and the manual review function will be forcibly enabled.

Constraints

Only tenant accounts support review configuration.

Configuring a Script Review Policy

  1. Log in to COC.
  2. In the navigation pane, choose Resource O&M > Automated O&M.
  3. In the Routine O&M area, click Script Management. The script management page is displayed.
  4. On the displayed Custom Scripts tab page, click Review Configurations.
  5. In the displayed review configuration drawer, set parameters related to script review.

    Table 1 Parameters of review configuration

    Parameter

    Description

    Manual Review

    This function is disabled by default.

    • If this function is disabled, you do not need to set other parameters.
    • If this function is enabled, you can select a risk level for your script. If you select the same risk level when creating a script, this script will be forcibly reviewed.

    Risk Level

    This parameter needs to be set when manual review is enabled. The script risk level can be High, Medium, or Low.

    During a custom script creation, if you select the same risk level as that selected in manual review configuration, this script needs to be reviewed and the enterprise project, reviewer, and notification method will be automatically configured to the values you set in the review configuration.

    Enterprise Project

    This parameter needs to be set when manual review is enabled.

    Select an enterprise project from the drop-down list.

    Reviewer

    This parameter needs to be set when manual review is enabled.

    Select Shift or Individual.
    • Shift: Select a shift scenario and a role from the drop-down lists based on the configured values. For details about how to configure a shift, see Shift Schedule Management.
    • Individual: Select a user as the reviewer. For details about how to configure a reviewer, see Personnel Management.

    Notification Mode

    This parameter needs to be set when manual review is enabled.

    Notification method for notifying the reviewer. Select a notification method from the drop-down list.

    • Default: The notification method selected in the subscription notification settings of the reviewer is used by default. For details about how to set the default notification method, see Selecting a Notification Method.
    • SMS, WeCom, DingTalk, Phone, Lark, and Email: Notifications are sent based on the information reserved by the reviewer. For details about how to set the reviewer information, see Modifying Personnel Information.
    • No Notification: No notifications are sent when a review is started.

  6. Click OK. The review configuration is complete.

    For scripts created after the configuration is successful, if the risk level selected in the review configuration is selected, manual review will be forcibly enabled.