Loading…
Require a named approver before any Zap releases spend over $500 — the approval becomes a signed verdict, not a thumbs-up.
For: Ops and finance teams running spend workflows in Zapier
Escalates any spend release at or above $500 to the named approver.
Blocks a release when the approver's authority limit is below the amount.
Blocks a release where the requester and the approver are the same person.
# Zapier Spend-Approval Gate ($500+)
# Fork: drop the "Create Decision Dossier" action ahead of the protected step
# in your Zap and map amount / requester / approver.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: zapier-approval-over-500
surface: zapier
workflow_key: discretionary_spend_release
standards: [SOC2-CC8.1, ISO27001-A.5.15]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: approval_threshold
when: "action == 'spend.release'"
decision: |
ALLOW IF amount_usd < 500
ESCALATE OTHERWISE
reason_code: spend_over_approval_threshold
- name: approver_authority_check
when: "action == 'spend.release'"
decision: |
BLOCK IF approver.authority_limit_usd < amount_usd
ALLOW OTHERWISE
reason_code: approver_authority_insufficient
- name: self_approval_block
when: "action == 'spend.release'"
decision: |
BLOCK IF approver.email == requester.email
ALLOW OTHERWISE
reason_code: self_approval_not_permitted
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.