Skip to main content
Question

Peer review for changes made by Jamf admins

  • August 4, 2026
  • 4 replies
  • 62 views

Rinaldy
Forum|alt.badge.img

Hi team,

We are looking to strengthen our change management and security controls within Jamf Pro. Specifically, we're exploring ways to implement a peer review workflow for high-risk payloads like Config profiles, policies and scripts.

Currently, any admin with edit permissions can save and deploy those changes immediately. For us, having a single admin able to make immediate, wide-reaching changes introduces significant risk—whether from accidental misconfiguration or compromised admin credentials.

We’ve considered reducing the permission scope of admins and granting limited time admin elevations,  but we’re mostly interested in payload-level security here which we think is best to solve the problem.

Curious to hear if you’ve thought of this, or if there’s any non-native way to solve it.

I tried searching through the this forum and the mac-admins slack but couldn’t find any previous discussions on it. Feel free to point me to one if it already exist.

Thanks!

4 replies

woaikonglong
Forum|alt.badge.img+9
  • Jamf Heroes
  • August 4, 2026

If I had wisdom on this, I’d offer it, but all I have are reasons it could really be beneficial!


thebrucecarter
Forum|alt.badge.img+16

We had a “two person rule” in effect, until our group dropped to 1/3 of its previous size.  Now it’s back to the wild west again...


Rinaldy
Forum|alt.badge.img
  • Author
  • New Contributor
  • August 4, 2026

We had a “two person rule” in effect, until our group dropped to 1/3 of its previous size.  Now it’s back to the wild west again...

@thebrucecarter yes a “two person rule” is what we’re looking for. Curious, were you able to enforce this?


thebrucecarter
Forum|alt.badge.img+16

We had a “two person rule” in effect, until our group dropped to 1/3 of its previous size.  Now it’s back to the wild west again...

@thebrucecarter yes a “two person rule” is what we’re looking for. Curious, were you able to enforce this?

Only procedurally, not technologically.  Although, we are looking at front-ending certain operations through ServiceNow API integration with Jamf and forcing it there.