Currently the only way to prevent applies of un-approved PRs is via Access Policy [EE feature] in the Management Repo Atlantis has a simple `apply_requirements` config options; it might make sense to have smth similar in Digger CE