Hi team,
We are looking to strengthen our change management and security controls within Jamf Pro. Specifically, we're exploring ways to implement a peer review workflow for high-risk payloads like Config profiles, policies and scripts.
Currently, any admin with edit permissions can save and deploy those changes immediately. For us, having a single admin able to make immediate, wide-reaching changes introduces significant risk—whether from accidental misconfiguration or compromised admin credentials.
We’ve considered reducing the permission scope of admins and granting limited time admin elevations, but we’re mostly interested in payload-level security here which we think is best to solve the problem.
Curious to hear if you’ve thought of this, or if there’s any non-native way to solve it.
I tried searching through the this forum and the mac-admins slack but couldn’t find any previous discussions on it. Feel free to point me to one if it already exist.
Thanks!
