Compliance configuration
Turn on DORA major-incident classification
Enable the DORA major-incident classification toggle and understand what it commits you to.
This guide enables the dora_major_incident_classification regulatory toggle, which lets agents classify incidents against the DORA major-incident criteria. It is one of the 16 regulatory toggles in the toggle catalog.
Before you start. This is a sticky toggle. The first time you classify an incident as DORA major, the toggle locks on and can only be switched off later through a dual-approval request. Read why toggles are sticky first if that is new to you.
Prerequisites
- A role that grants
settings.featureflags.toggle-- the platform owner and tenant administrator have it (see the role catalog). - MFA satisfied for your session (both roles above require MFA).
Steps
- Go to Settings -> Regulatory features.
- Find the DORA major-incident classification toggle -- it is the
dora_major_incident_classificationflag, listed under the DORA regulation. - Enable it. The change is audited.
It can also be enabled in bulk at signup by choosing the eu_financial or regulated_eu_compliance_floor bundle -- see signup bundles.
What this commits you to
- Agents can now classify incidents as DORA major.
- The toggle defaults off and is forward-only: turning it on does not retroactively reclassify past incidents.
- Once the first incident is classified DORA major, the toggle becomes sticky. Switching it back off then requires a dual-approval request, because the regulator expects retention and reporting obligations to persist once you have produced regulated artifacts.
Verify
- The DORA classification action appears on the incident detail view.
- The audit log shows one entry for the toggle change.