Updated on 2026-06-23 GMT+08:00

Configuring Change Control

After change control is enabled, authorization must be performed based on incident tickets, war room tasks, and change tickets. O&M personnel need to handle corresponding tickets based on the specific scenario before applying for temporary operation permissions. Privilege escalation requests that are not associated with a ticket will be blocked. In this way, permissions are strongly bound to O&M scenarios, preventing unauthorized operations that are not planned or approved.

Figure 1 Change control process

Prerequisites

You have enabled change control and applied for corresponding IAM permissions. The action IDs are listed in the following table.

Table 1 Authorization description

Authorization Type

Action ID

Role/Policy

  • iam:roles:listRoles
  • iam:permissions:grantRoleToAgency
  • iam:permissions:grantRoleToAgencyOnDomain
  • iam:roles:createRole
  • iam:groups:listGroups
  • iam:permissions:listRoleAssignments
  • iam:permissions:grantRoleToGroupOnDomain
  • iam:permissions:revokeRoleFromGroupOnDomain
  • iam:permissions:revokeRoleFromGroupOnDomain
  • iam:roles:deleteRole
  • iam:roles:updateRol

Identity Policy

  • iam:policies:createV5
  • iam:policies:listV5
  • iam:groups:attachPolicyV5
  • iam:groups:detachPolicyV5
  • iam:policies:deleteV5
  • iam:policies:listVersionsV5
  • iam:policies:createVersionV5
  • iam:policies:deleteVersionV5

Precautions

  • After ticket privilege escalation is enabled, northbound interfaces cannot be used. For example, if the privilege escalation of a script ticket is enabled, the northbound script interface cannot be used.
  • By default, change control policies of COC can only be bound to the functions of user groups. Do not use them for other purposes.
  • You can click the editing button for actions on the related COC page to determine whether to enable the corresponding functions. Note: All operations must be performed on COC. Do not directly edit a policy.
  • After you enable ticket privilege escalation, if there is a policy bound to a related user group, you need to unbind the policy from the user group before disabling ticket privilege escalation.
  • During ticket privilege escalation, regions, applications, and ticket statuses of a resource will be verified. If the resource does not belong to any region or application, no verification will be performed and all tickets of the user will be displayed. The following table describes the status verification of each type of ticket.
    Table 2 Ticket status verification

    Ticket Type

    Description

    Incident ticket

    • P1, P2, P3, and P4 incident tickets must be in the accepted state.
    • The application of privilege escalation must be the same as that in the incident ticket analysis and handling phase.
    • The operator of privilege escalation must be the owner in the incident ticket analysis and handling phase.
    • The region of privilege escalation must be the same as that specified in the incident ticket.

    War room

    • A war room must be in the started or fault demarcation state.
    • The application of privilege escalation must be an affected application handled in the war room.
    • The operator of privilege escalation must be the fault rectification owner, fault rectification member, or manager of the war room.

    Change ticket

    • The region and application of privilege escalation must be the same as those specified in the change ticket.
    • The operator of privilege escalation must be the executor of the change ticket.
    • The current operation time must be within the planned time window of change ticket execution. (The current operation time must be later than the planned start time and earlier than the planned end time.)
    • You must click Change Start for a change ticket.

Configuring Change Control

  1. Log in to COC.
  2. In the navigation pane, choose Change Ticket Management > Change Control.
  3. Click (Enable Work Order Authorization).

    Service ticket authorization is disabled by default and can be enabled. After this function is enabled, all actions performed on the COC platform will be displayed in the list.

  4. Click Associate Policy. The system automatically generates policies used for change control.
  5. Select a user group to which the policy is to be added.
  6. Click OK. The system adds the policies automatically generated in 4 to the selected user group.
  7. In the action list, locate an action whose control rule needs to be modified and click Modify in the Operation column.

    Only when the Interconnected column is Yes, the located action can be modified.

  8. Modify the ticket type as required.

    Table 3 Parameters for modifying a ticket type

    Parameter

    Description

    Enable Service Ticket Authorization

    The options are Enable and Disable.

    • Enable indicates that privilege escalation using a ticket is required.
    • Disable indicates that privilege escalation using a ticket is not required for all accounts in this scenario.

    Ticket Type

    The options are Change ticket, Incident ticket, and War room.

    Multiple options can be selected.

    Automatic Ticket Creation

    The options are Yes and No.

    • If you select Yes, an approved change ticket will be automatically created when you perform a change operation.
    • If you select No, an approved change ticket will not be automatically created when you perform a change operation. An existing service ticket will be matched and verified.

  9. Click OK.

    If service ticket authorization is enabled, O&M personnel need to associate the change task with a service ticket based on the specific change scenario to apply for corresponding operation permissions.

    For example, if service ticket authorization is enabled for a scheduled task, you need to associate the task with a service ticket when enabling the task.

    Figure 2 Enable service ticket authorization
    Figure 3 Starting a scheduled job
    Figure 4 Change authentication