Loading…
Every spend approval ping above $5k carries the policy snapshot, the requester's authority, and a public verify URL.
For: Ops and finance teams releasing discretionary spend from Slack
Escalates a discretionary spend release above $5,000 to the named approver.
Blocks a release where requester and approver are the same person.
Restrains a release that would take the cost centre past its remaining budget.
# Slack Discretionary-Spend Gate
# Fork: set the threshold and cost-centre budget source for your org.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: slack-discretionary-spend-gate
surface: slack
workflow_key: discretionary_spend_release
standards: [SOC2-CC8.1, ISO27001-A.5.15]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: spend_threshold
when: "action == 'spend.release'"
decision: |
ALLOW IF amount_usd < 5000
ESCALATE OTHERWISE
reason_code: spend_over_approval_threshold
- name: self_approval_block
when: "action == 'spend.release'"
decision: |
BLOCK IF approver.email == requester.email
ALLOW OTHERWISE
reason_code: self_approval_not_permitted
- name: budget_headroom_check
when: "action == 'spend.release'"
decision: |
RESTRAIN IF amount_usd > cost_centre.remaining_budget_usd
ALLOW OTHERWISE
reason_code: exceeds_cost_centre_budget
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Installs with no code. The Decionis app sits beside Slack approvals and records a Decision Dossier for every routed request.
1. Install Decionis from the Slack Marketplace.
2. /decionis → "Connect a workflow" → pick refund_approval (or any of the starter packs).
3. The app runs in observation mode out of the box: every Slack approval still
flows the same way, plus a signed Decision Dossier is recorded alongside it.