# Review Terraform before applying — acceptance checklist

Record evidence for every checked item. Unchecked or untested is not a pass. This checklist does not execute an integration or authorise external actions.

## Required inputs

- [ ] Terraform source, lockfile, backend identity and a fixed revision.

- [ ] A saved plan or authorised non-production planning environment and the intended change.

## Output checks

- [ ] The plan belongs to the intended revision, workspace and lockfile.

- [ ] Every replacement or deletion has an explicit rationale.

- [ ] Secret-bearing plan/state content is excluded from shared evidence.

- [ ] Recovery feasibility is checked per resource before apply is considered.

## Deliverables

- [ ] Version/backend record

- [ ] Validation and plan receipts

- [ ] Resource-impact table

- [ ] Apply decision and recovery note

## Evidence and decision

Evidence links: [fill in]
Untested paths: [fill in]
Unresolved findings: [fill in]
Reviewer: [fill in]
Decision and scope: [fill in]

## Boundaries

- Terraform MCP includes workspace and run mutations when credentials and tools permit them. Registry lookup is not a read-only guarantee for the full server.

- The agent grants editing and terminal tools; approval language does not enforce permissions. Plans can contact providers, and backend/refresh behaviour is version-sensitive.

Workflow: https://undominated.ai/workflows/#review-a-terraform-plan
