Loading…
Evaluate any Make scenario before its protected module runs, using the HTTP V4 request recipe and the bearer key in Make's keychain.
For: Ops teams building scenarios in Make that touch money or customer records
Escalates when a protected module would run above the encoded value threshold.
Restrains a scenario run that arrives without a stable idempotency key.
Blocks a scenario acting on a record the connected account is not entitled to.
# Make Scenario Execution Gate
# Fork: paste the HTTP V4 request ahead of the protected module and map the
# response's verdict + dossier id into the scenario router.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: make-scenario-execution-gate
surface: make
workflow_key: scenario_execution
standards: [SOC2-CC8.1, ISO27001-A.5.15]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: protected_module_gate
when: "module.protected == true"
decision: |
ALLOW IF amount_usd < 2000
ESCALATE IF amount_usd < 25000
BLOCK OTHERWISE
reason_code: protected_module_over_threshold
- name: idempotency_requirement
when: "always"
decision: |
RESTRAIN IF request.idempotency_key == null
ALLOW OTHERWISE
reason_code: missing_idempotency_key
- name: entitlement_check
when: "always"
decision: |
BLOCK IF record.owner_org != connection.org_id
ALLOW OTHERWISE
reason_code: record_not_entitled
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.