For example, at my work this is what i do to apply changes to our AWS setup:
1. Fetch the latest version of our git repo.
2. Create a new git branch named after the Jira ticket im working on.
3. Solve the jira ticket by modifying the terraform code accordingly.
4. Submit a pull request and assign one of my colleagues as reviewer.
5. They review my solution, tell me to correct some issues that there might be, or straight up approves my solution.
6. My PR is merged into master.
7. I download the latest master version and apply the codebase.
This way we always have at least two people verify any changes to our infrastructure, minimizing the risk of fuckups and ensures solutions are as good as possible.