Creating a vCAB
Required Information
| Field | Description |
| Name | Descriptive name (e.g., Security Review Board) |
| Description | Purpose and scope of the vCAB |
| Approval Type | Unanimous, Majority, or Quorum |
| Members | Users who will vote on changes |
Optional Settings
| Field | Description |
| Quorum Count | Required approvals (only for Quorum type) |
| Chair Can Veto | Enable chair veto power |
| Chair Can Break Ties | Enable chair veto power |
| Require All Mandatory | Block decisions until mandatory members vote |
Member Configuration
- Member Type - Chair or Voting
- Mandatory - Whether their vote is required
- Approval Role - Optional display tag
Best Practices
- One chair per vCAB - Multiple chairs can cause confusion
- Odd number of voting members - Reduces tie scenarios
- Mark key stakeholders as mandatory - Ensures critical input
Editing a vCAB
What Can Be Changed and the effect
| Setting | Effect on Pending Changes |
| Name/Description | No effect |
| Approval Type |
Applies to new changes only
|
| Quorum Count |
Applies to new changes only
|
|
Chair Powers
|
Applies immediately to all changes associated
|
|
Add Member
|
New member doesn't affect pending changes
|
| Remove Member |
Removed member's votes still count
|
| Change Member Type |
Applies to new changes only
|
Why This Matters
- Consistency - Changes are evaluated by original reviewers
- Audit Trail - Vote history is preserved
- No Gaming - Can't add/remove members to influence outcome
Archiving a vCAB
- Sets is_active = False
- vCAB no longer appears in selection lists
- Cannot be used for new changes
- Existing changes continue to completion
- Historical data preserved
Approval Roles
Approval roles are optional tags that help identify member expertise.
Creating Roles
- Name - e.g., "Security Lead", "Architecture"
- Description - Role responsibilities
- Color - Visual identifier
Using Roles
- In the vCAB member list
- On vote status displays
- In approval notifications
Example Roles
| Role | Color | Description |
| Security Lead | Red | Reviews security implications |
| Architecture | Blue | Evaluates technical design |
| Operations | Green | Assesses operational impact |
| Compliance | Purple | Ensures regulatory compliance |
Troubleshooting
- The change continues with original voters
- Or resubmit the change to get new vote records
- Mandatory members - Have all mandatory members voted?
- Approval type - Is the threshold actually met?
- Chair tie-break - Is it a tie requiring chair decision?