Loading…
Access, change, and procurement gates for internal automation — prove every sensitive change followed the approved path.
For: Mid-market IT, security, platform ops
Requires a timed, approved dossier for sensitive access and change workflows.
Adds a timed dossier and revocation trail for temporary admin rights.
Blocks unapproved OAuth and SaaS procurement events before signup.
# IT Ops Pack
# Fork: the three gates from the it_ops starter pack, with your thresholds.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: it-ops-pack
surface: servicenow
policy_pack_id: it_ops
standards: [SOC2-CC6.2, ISO27001-A.5.18]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: access_change_gate
when: "request startswith 'access.'"
decision: |
ESCALATE IF approval_dossier == null
ALLOW OTHERWISE
reason_code: access_change_without_dossier
- name: just_in_time_access
when: "request == 'access.temporary_admin'"
decision: |
BLOCK IF requested_duration_hours > 8
ESCALATE IF revocation_scheduled_at == null
ALLOW OTHERWISE
reason_code: jit_window_or_revocation_missing
- name: software_procurement_gate
when: "action in ['oauth.grant', 'saas.signup']"
decision: |
BLOCK IF vendor.id not in approved_software_catalog
ALLOW OTHERWISE
reason_code: unapproved_software_procurement
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.