Turn a DNS edit into a controlled change plan

Name the owners, evidence, smallest action, stop condition, verification, and rollback before touching a control plane. The planner identifies missing decisions; it never approves execution.

1. Outcome and risk
Affected service surfaces
2. Owners and window

Select a risk level before deciding which mutation controls are required.

3. Preflight evidence

Clear any statement that is not yet proven. An unchecked item becomes a stop condition for state-changing plans.

4. Action, stop, verification, and rollback

Draft assessment

Untitled change draft

Draft blocked

9 required items must be resolved before this draft is reviewable.

Risk
Not selected
Affected surfaces
0
Preflight confirmed
0/7

Resolve before review

  • Name the planned operation.
  • Define the user-visible outcome.
  • Select the highest applicable risk level.
  • Select at least one affected service surface.
  • Name the change owner.
  • Name an independent verifier.
  • Define one smallest coherent action.
  • Define an explicit stop condition.
  • Define verification from authority outward.

Ownership and window

  • Change owner: Not named.
  • Approver: Risk not selected.
  • Independent verifier: Not named.
  • Window: Risk not selected.
  • Maximum acceptable interruption: Risk not selected.

Preflight and affected surfaces

  • Review: No affected surface selected.
  • Select a risk level before relying on preflight confirmations.

One coherent action and stop

  • The action is not defined.
  • Stop when: No stop condition is defined.
  • After the first unexplained result, stop adding changes.

Verification

  • The verification plan is not defined.
  • Record the exact query or check, observer, answer or result, TTL where relevant, and time.
  • Do not report a global propagation percentage.

Rollback

  • Select a risk level before deciding whether rollback is required.

Planner cautions

  • This planner checks whether a draft contains required evidence and decisions. It cannot approve a change or prove the entered facts are correct.
  • A rollback is another DNS change. Restoring authoritative data cannot erase values already held by caches.

Planner boundaries

Read the complete safe DNS-change checklist and the cache-aware rollback playbook before executing a risky change.