Are you arguing that it’s a good idea for random developers to be able to set up new subdomains on the company domain without any oversight?
Alternatively, yup, SOC2 is a thing: optionally create a ticket tracking the why, then open a PR against the IaC repo citing that ticket, have it ack-ed by someone other than the submitter, audit trail complete, change managed, the end