# Terraform change review

Blank working document. Replace placeholders with your own evidence; an empty field is unknown, not a passing result.

Owner: [fill in]
Source revision: [fill in]
Environment: [fill in]
Evidence date: [fill in]

## Identity

Revision: ___
Terraform/provider versions: ___
Lockfile hash: ___
Backend/workspace/account: ___

## Plan evidence

Plan command/process: ___
Plan timestamp/hash: ___
Validation output: ___
Refresh or external-data effects: ___

## Impact

| Resource | Planned action | Requirement | Destructive/replacement risk | Recovery |
| --- | --- | --- | --- | --- |
| ___ | ___ | ___ | ___ | ___ |

## Decision

Unexplained actions: ___
Backup/restore evidence: ___
Approver and maintenance window: ___
Apply status: not authorised by this worksheet

## Boundaries

- Terraform MCP includes workspace and run mutations when credentials and tools permit them. Registry lookup is not a read-only guarantee for the full server.

- The agent grants editing and terminal tools; approval language does not enforce permissions. Plans can contact providers, and backend/refresh behaviour is version-sensitive.

Workflow: https://undominated.ai/workflows/#review-a-terraform-plan

Original worksheet: MIT. Linked resources retain their own licences and setup requirements.
