Protect and secure your data from cyber attacks
Data Protection
Data Security
Data Insights
The 5 Steps to Cyber Resilience
Cloud & SaaS
Enterprise
Industries
The gap between "approved" and "allowed to run" is where governance breaks. This new capability closes it.
Consider this scenario. It’s Tuesday, and your change advisory board (CAB) signs off on revoking a service account's elevated privileges, rotating an encryption key, or clearing a legal hold. But the actual change cannot touch production until the Saturday night maintenance window. That is when you have support personnel on standby to troubleshoot or perform a rollback if required.
In the meantime, somebody must manage the approved, but not yet run change. You must keep the ticket open without letting it go stale. You need to avoid triggering a second CAB cycle by touching it early. And you definitely don’t want to wake an approver at 2 a.m. to re-sign off the change just because the window finally opened.
That in-between period is when governance quietly breaks down. Multi-person approvals only hold up if it fits how change actually happens in your organization. Force approval and execution into the same moment, and people find a way around it. It’s common to rush a sign-off just to catch an open change window, or to pull an approver in at 2 a.m. because the system left no other option. That's not governance working—that's governance being tolerated.
This is why Cohesity just released a new quorum feature—deferred execution. Approve a quorum-protected action during your change control approval schedule, then execute the action when the maintenance window opens.
Quorum is a Cohesity Data Cloud feature that requires two or more authorized individuals to approve a critical change before it can happen—like a safety deposit box that needs both your key and someone else’s to open. But customers have told us that their enterprise change management rarely moves at the speed of a single approval.
If you're operating under ITIL, SOX, or any formal change-control process, the people reviewing a change and the people executing it are often working from completely different calendars. Your CAB meets mid-week. Your window to touch production might be Saturday morning. You need quorum controls that support these divided workflows, and now you have them in Cohesity Data Cloud.
Deferred execution sits alongside the approve and run-immediately quorum flow you already know. The new capabilities do not replace existing processes, nor do they affect your existing quorum groups, thresholds, or approval logic. Deferred execution allows you to approve an action now, but not actually execute the action until some defined point in the future.
How it works:
Here’s what deferred execution offers:
Multi-person approval only works if it fits how your organization runs change control. The moment a control gets in the way of your operational reality, people find ways around it. Deferred execution lets quorum bend to fit your process instead of the other way around. Best of all, you don’t have to give up any of what makes quorum worth using in the first place: separation of duties, no unilateral action, and a clear record of what happened.
If you are in financial services, healthcare, government, or any organization running a formal CAB process, this closes a real, practical gap between “we approved it” and “we are allowed to run it.” And it does it with more rigor than a basic pre-authorization checkbox: enforced windows, permissions checked again at execution time, one-shot execution, full audit logging.
Deferred execution is available now as part of Cohesity Data Cloud, and it works with the existing quorum groups and approval policies you've already configured.
Read the quorum section of the Admin Guide for the full walkthrough.
Written By
Gautam Roy
Product Manager