Loading
September 25 2026

Cohesity Data Cloud introduces deferred execution for quorum

The gap between "approved" and "allowed to run" is where governance breaks. This new capability closes it.

Image Cohesity Data Cloud introduces deferred execution for quorum

Consider this scenario. It’s Tuesday, and your change advisory board (CAB) signs off on revoking a service account's elevated privileges, rotating an encryption key, or clearing a legal hold. But the actual change cannot touch production until the Saturday night maintenance window. That is when you have support personnel on standby to troubleshoot or perform a rollback if required. 

In the meantime, somebody must manage the approved, but not yet run change. You must keep the ticket open without letting it go stale. You need to avoid triggering a second CAB cycle by touching it early. And you definitely don’t want to wake an approver at 2 a.m. to re-sign off the change just because the window finally opened.

That in-between period is when governance quietly breaks down. Multi-person approvals only hold up if it fits how change actually happens in your organization. Force approval and execution into the same moment, and people find a way around it. It’s common to rush a sign-off just to catch an open change window, or to pull an approver in at 2 a.m. because the system left no other option. That's not governance working—that's governance being tolerated.

This is why Cohesity just released a new quorum feature—deferred execution. Approve a quorum-protected action during your change control approval schedule, then execute the action when the maintenance window opens. 

Why you need quorum controls

Quorum is a Cohesity Data Cloud feature that requires two or more authorized individuals to approve a critical change before it can happen—like a safety deposit box that needs both your key and someone else’s to open. But customers have told us that their enterprise change management rarely moves at the speed of a single approval. 

If you're operating under ITIL, SOX, or any formal change-control process, the people reviewing a change and the people executing it are often working from completely different calendars. Your CAB meets mid-week. Your window to touch production might be Saturday morning. You need quorum controls that support these divided workflows, and now you have them in Cohesity Data Cloud. 

How deferred execution works

Deferred execution sits alongside the approve and run-immediately quorum flow you already know. The new capabilities do not replace existing processes, nor do they affect your existing quorum groups, thresholds, or approval logic. Deferred execution allows you to approve an action now, but not actually execute the action until some defined point in the future.

How it works:

  1. You request approval to take an action in a specified window. When submitting a quorum-protected operation, you can set an execution window: a start and end time for when the action is allowed to run.
  2. Your approvers do what they have always done. The quorum group reviews and approves the request in the familiar way. The existing approval expiration rules still apply, so nothing sits waiting for quorum indefinitely.
  3. The window opens. Once quorum is met and your window arrives, the request becomes ready to execute, and the requester gets notified.
  4. You execute during the window. Inside the window, the requester who made the original request triggers execution. 
  5. Miss the window, and it expires. If the window closes before anyone executes, the approval expires. It does not run automatically after the fact. If you still need the action done, you need to request a new quorum approval.

Deferred execution in practice

Here’s what deferred execution offers: 

  • A real execution window. Cohesity Data Cloud enforces both sides of it. Try to jump the start time, and the platform won't let you. Run past the end time and the approval is simply gone. 
  • One window, every time zone.  The window is captured in the requester's own time zone, but stored internally as UTC. This way, an approver on the other side of the world sees an accurate local time instead of doing the math. If your approval chain spans a few continents, that alone saves people from second-guessing whether a window is still open.
  • One approval, one execution. Once approved, a request can only run once. If it fails partway, you’ll be notified immediately. That way, you can go ahead and redo the process.
  • Cohesity Data Cloud double-checks your permissions when you run the action, not just when it was approved. Getting approval on Tuesday does not automatically mean the requester is still authorized for the operation on Saturday. Before executing the action, Cohesity Data Cloud verifies again that the requester still has sufficient permissions to take it.  
  • No risk of collision. Say a deferred request is sitting approved, and waiting for its window, or waiting inside the window to be run. Nobody can request a second change against the specific object the quorum-protected action is acting against, e.g., the backup, the cluster, or the retention policy. Everything else on the cluster carries on as normal.
  • Full audit trail, end to end. The actions associated with this operation (deferred, window opened, executed, expired) are all logged, with the time zone context attached. You can confidently answer “who approved this, and when did it run” without digging through old emails.

Closing the gap between “approved” and “allowed to run”

Multi-person approval only works if it fits how your organization runs change control. The moment a control gets in the way of your operational reality, people find ways around it. Deferred execution lets quorum bend to fit your process instead of the other way around. Best of all, you don’t have to give up any of what makes quorum worth using in the first place: separation of duties, no unilateral action, and a clear record of what happened.

If you are in financial services, healthcare, government, or any organization running a formal CAB process, this closes a real, practical gap between “we approved it” and “we are allowed to run it.” And it does it with more rigor than a basic pre-authorization checkbox: enforced windows, permissions checked again at execution time, one-shot execution, full audit logging.

Getting started

Deferred execution is available now as part of Cohesity Data Cloud, and it works with the existing quorum groups and approval policies you've already configured. 

Written By