I don't understand the problem. Use something like `terraform plan` as a comment on the pull request and manually look over the changes before pulling in.
I don't use Terraform but I think you're describing something like Atlantis? https://www.runatlantis.io/ I remember seeing a team running this at a previous company I worked at
Atlantis is just like the GP's mentioned: a CI to run terraform plan then a person needs to examine the dryrun output. But it's still not ideal because Atlantis also has persmissions on production, and a (human) mistake could brought down your infrastucture.
Not even before pulling in - the state may change in between the comment and the applying. A safer way is to dump the plan from after the merge and not apply that specific plan until after it's manually approved.