Loading…
Blocks unapproved OAuth grants and SaaS signups before anyone clicks through the terms.
For: IT procurement and security reviewing shadow-IT signups
Blocks an OAuth grant or SaaS signup for a vendor outside the approved catalog.
Escalates an OAuth grant requesting broader scopes than the catalog entry authorized.
Restrains procurement of a tool that processes data outside the allowed regions.
# ServiceNow Software Procurement Gate
# Fork: point approved_software_catalog at your own CMDB / vendor list.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: servicenow-software-procurement-gate
surface: servicenow
workflow_key: software_procurement
standards: [SOC2-CC6.1, ISO27001-A.5.19]
defaults:
mode: shadow
emit_dossier: true
allowed_regions: [EU, US]
rules:
- name: approved_catalog_requirement
when: "action in ['oauth.grant', 'saas.signup']"
decision: |
BLOCK IF vendor.id not in approved_software_catalog
ALLOW OTHERWISE
reason_code: unapproved_software_procurement
- name: scope_creep_escalation
when: "action == 'oauth.grant'"
decision: |
ESCALATE IF requested_scopes not subset_of catalog_entry.authorized_scopes
ALLOW OTHERWISE
reason_code: oauth_scope_exceeds_catalog
- name: data_residency_restraint
when: "action == 'saas.signup'"
decision: |
RESTRAIN IF vendor.processing_region not in allowed_regions
ALLOW OTHERWISE
reason_code: processing_region_not_allowed
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.