> For the complete documentation index, see [llms.txt](https://user.netmera.com/netmera-user-guide/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://user.netmera.com/netmera-user-guide/web-tools/tag-manager/security-review.md).

# Tag manager security review

Tag Manager security review requires a second authorized user to approve a version before publishing.

Security review is an optional approval step that sits between finishing a Tag Manager version and publishing it. Instead of one person building and publishing in a single action, one user prepares the version and a second, authorized user reviews it and decides whether it reaches the live site.

{% hint style="info" %}
Security review is optional and disabled by default. To enable it for an app, contact your Netmera account manager. While it is disabled, Tag Manager behaves exactly as documented elsewhere in this guide and none of the elements below appear in the panel.
{% endhint %}

### Why use it

Every Tag Manager publish injects JavaScript and other assets into the live site. Organizations with strict change-control or information-security policies — banks, fintechs, insurers, public institutions — usually require a second pair of eyes before anything reaches production.

With security review enabled:

* No version reaches the site without an explicit approval.
* Every published version carries a named approver.
* Every version keeps a full record of who requested, approved, or rejected it, and why.
* The approval cannot be bypassed: publish endpoints called directly are rejected while the flow is enabled.

### Roles

| Role                                                                | What it can do                                                                                                                                                                                                          |
| ------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Creator</strong><br>Any user with Tag Manager access</p> | Creates tags, triggers, and variables, and sends versions to review. Forks and previews any version, including one waiting for review. Cannot publish directly — Approve, Reject, and Download Version are not visible. |
| <p><strong>Security Reviewer</strong><br>Approver</p>               | Everything a Creator can do, plus approving or rejecting the version waiting for review, and downloading any version file.                                                                                              |

{% hint style="warning" %}
Assign the **Security Reviewer** role to at least one panel user before security review is enabled. Without a reviewer, versions sent to review cannot be approved and publishing stops.
{% endhint %}

The same **Security Reviewer** role also covers [Web Personalization security review](/netmera-user-guide/web-tools/web-personalization/security-review.md) — one role is enough for both products.

### Send a version to review

{% stepper %}
{% step %}

#### 1) Build the version

Create or edit tags, triggers, and variables in **Workspace** as usual.
{% endstep %}

{% step %}

#### 2) Preview

Validate that triggers fire and variables resolve before involving a reviewer.
{% endstep %}

{% step %}

#### 3) Click Send to Review

When security review is enabled, the **Publish** button on the workspace page appears as **Send to Review**.
{% endstep %}

{% step %}

#### 4) Add a version note

A side panel opens for the version note. Describe what changed and why — this is the note the reviewer reads, and it is included in the notification email.
{% endstep %}

{% step %}

#### 5) Confirm

The version is snapshotted and moves to **Waiting Review**, and the panel opens **Version History**. All Security Reviewers receive an email.
{% endstep %}
{% endstepper %}

### Review a version

A Security Reviewer opens **Review Actions** either from the version detail page or from the **Actions** column in [Version History](/netmera-user-guide/web-tools/tag-manager/version-history.md).

* **Approve** — a publish note is entered, the standard publish flow runs, and the version becomes **Live**. If the publish fails, the version stays in **Waiting Review**, so there is no partly published state.
* **Reject** — a reject note can be entered, and the version becomes **Rejected**. A rejected version is not final: it can be edited and sent to review again.

### Version statuses

| Status             | Meaning                                                 |
| ------------------ | ------------------------------------------------------- |
| **Waiting Review** | Submitted and waiting for a Security Reviewer decision. |
| **Live**           | Approved and published to the site.                     |
| **Rejected**       | Reviewed and declined. Can be edited and resubmitted.   |

If a live version exists, the version waiting for review is listed first and the live version second. If there is no live version, the version waiting for review stands alone at the top.

### Audit trail

The version detail page records the full decision history:

* **Review Requested by** and date
* **Version Note** entered at submission
* **Approved by** and date, with the **Publish Note** — or **Rejected by** and date, with the **Reject Note**

Approved and Rejected fields appear only once a decision has been made.

### Notifications

| Event                  | Who is notified           | What the email contains                              |
| ---------------------- | ------------------------- | ---------------------------------------------------- |
| Version sent to review | All Security Reviewers    | Link to the version detail page and the version note |
| Version approved       | The user who submitted it | Link to the version detail page and the publish note |
| Version rejected       | The user who submitted it | Link to the version detail page and the reject note  |

Users without the Security Reviewer role receive no review notifications.

### Download Version

Security Reviewers see a **Download Version** button on every version — Waiting Review, Live, or Rejected — and can download the version file for offline inspection or archiving. The button is not visible to other roles, or when security review is disabled.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation by asking a question.

Perform an HTTP GET request on the following URL with the `ask` and `goal` query parameters:

```
GET https://user.netmera.com/netmera-user-guide/web-tools/tag-manager/security-review.md?ask=<question>&goal=<user_goal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is what the user is ultimately trying to achieve, the reason they need the answer. Sharing it helps GitBook give you a better, more relevant answer. A goal is most helpful when it describes the outcome the user wants rather than restating the question. For example, with `ask=how do I create an API token`, a goal like `automate deployments from our CI pipeline` lets GitBook tailor the answer to that use case.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
