Loading…
The starting policy for any point of execution: risk band, hard rules, and a signed dossier on every verdict.
For: Engineers wiring the gate into their own service before the action commits
Allows below the escalation threshold, escalates in the middle band, blocks above.
Hard rules win over the score — a restricted subject blocks regardless of band.
Restrains the action when the gate cannot be reached, so nothing commits unevaluated.
# Universal Action Gate Baseline
# Fork: this is the neutral starting shape. Replace risk_field and thresholds
# with the signal your own payload actually carries.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: sdk-universal-action-gate-baseline
surface: sdk
standards: [SOC2-CC8.1, ISO27001-A.8.32]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
risk_field: risk_score
rules:
- name: risk_band_routing
when: "always"
decision: |
ALLOW IF risk_score < 60
ESCALATE IF risk_score < 85
BLOCK OTHERWISE
reason_code: risk_score_over_threshold
- name: hard_rule_precedence
when: "always"
decision: |
BLOCK IF restricted == true
ESCALATE IF requires_human_approval == true
ALLOW OTHERWISE
reason_code: hard_rule_matched
- name: fail_closed_on_outage
when: "gate.reachable == false"
decision: |
RESTRAIN IF always
reason_code: gate_unreachable_fail_closed
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.