Don't author authority from scratch. Fork a ready-made recipe for a common high-stakes workflow, run it in the browser simulator, then deploy it in shadow mode. No signup to browse or fork.
53 executable policies across 8 verticals and 26 platforms. Filter by the platform you execute on and the vertical you run.
Showing all 53 policy packs
Velocity, discount, and market-eligibility gates for Shopify checkout, B2B, and POS — with audit evidence for every exception.
Never discount below margin. Holds the checkout before the payment token is issued when the cart would breach the floor.
Blocks fulfilling an order for stock oversold across channels — before the fulfillment token is issued.
Privileged-access and production-change controls for ServiceNow ITSM — proving every change followed the approved path.
Temporary admin rights get a timed dossier and a revocation trail — so the grant expires whether or not anyone remembers.
Blocks unapproved OAuth grants and SaaS signups before anyone clicks through the terms.
Toxicity, account-age, and brigading controls for automated moderation — with a signed reason for every removal.
Never let an agent run `rm -rf`, a force-drop, or a disk-level command without a human approval on the tool call.
Stops an agent reading, printing, or committing credential files, and escalates any command that would rotate a secret.
Holds agent-authored database migrations and `terraform apply` runs until a human signs the blast radius.
Never force-push to a protected branch, never rewrite shared history — the agent has to open a PR instead.
Blocks an agent installing a package from an unapproved registry or adding a dependency with no lockfile entry.
Scores every Codex tool call by blast radius and escalates anything that could touch production before it runs.
Only the tools you approved fire. Everything else is denied at the pre-tool boundary with a reason the agent can read.
Reserves projected model spend before the prompt is forwarded and restrains runs that would blow the project wallet.
Blocks production deploys during a freeze, escalates out-of-hours releases, and stamps the verdict on the PR.
Require review before a force push. Blocks history rewrites on protected branches and escalates protection-setting changes.
An agent can author the change; a human still has to sign the deploy. Restrains AI-authored diffs that touch deploy, infra, or migration paths.
Wrap `send_refund`, `issue_payout`, or any tool that moves money — the inner tool only fires on an approve verdict.
Drop a gate node between plan and execute so the graph's conditional edge branches on the verdict instead of a guess.
Gates retrieval and external API calls that touch regulated records — restricted subjects never leave the boundary.
The starting policy for any point of execution: risk band, hard rules, and a signed dossier on every verdict.
Gate an inbound webhook before it mutates state — replay protection, signature checks, and a dossier per delivery.
Opens sandbox egress only for the exact target the grant covers, and stops a run that would blow the account budget.
Gates the extension call a Vertex AI model wants to make, so an out-of-scope or unapproved tool never executes.
Require a named approver before any Zap releases spend over $500 — the approval becomes a signed verdict, not a thumbs-up.
Blocks an invoice or payment instruction from a domain that is not on the verified-vendor list before the Zap pays it.
Lets the Zap issue refunds that sit inside policy and holds the rest — with the reason code attached to the record.
Pauses a Zap the moment a customer's risk score crosses the line, instead of letting the automation keep firing.
Evaluate any Make scenario before its protected module runs, using the HTTP V4 request recipe and the bearer key in Make's keychain.
Call the evaluate endpoint from an HTTP Request node and branch the workflow on the verdict before the write step runs.
Never let an automation or agent move an opportunity above $1M into Closed Won without the approval chain.
Escalates quote discounts past the encoded band when the contract-value evidence is missing.
Holds account changes on regulated or restricted customers until the right reviewer signs the record.
Turns the refund approval that happens in a Slack thread into a signed verdict carrying the policy version and reviewer authority.
Every spend approval ping above $5k carries the policy snapshot, the requester's authority, and a public verify URL.
Holds a vendor payment run until the bank details, sanctions evidence, and dual approval all check out.
Stops a purchase order releasing to an unapproved supplier or past the requester's authority limit.
Catches an out-of-band payroll run — a bank-detail change, an off-cycle payment, a headcount jump — before the money leaves.
When a termination event lands, prove access and payroll were actually revoked — not just ticketed.
Never discount below margin. Holds a WooCommerce checkout whose net margin would breach the encoded floor.
Catches a pricing feed or AI engine publishing a price far off the last-known-good value before shoppers see it.
Folds eBay final-value fees and promoted-listing rates into the margin check before a listing or price change goes live.
Blocks fulfilling an order for stock oversold across channels, and checks referral plus fulfillment fees against the margin floor.
Folds the Walmart Marketplace referral fee into the margin gate before an order is acknowledged.
Stops a viral-spike order releasing on stock you do not have, or on a creator-commission stack that breaks margin.
Over-selling, margin-floor, and coupon-stacking gates for orders and fulfillment — the three that leak the most money.
Velocity, sanctions, and treasury movement controls — automated proof of every KYC, AML, payout, and limit decision.
Cloud spend, discount, and entitlement gates — stop runaway burn, margin leakage, and unsupported entitlement changes.
Access, change, and procurement gates for internal automation — prove every sensitive change followed the approved path.
Fairness, approval-chain, and offboarding gates — prove every hire, promotion, and termination cleared its checks.
Token budgets, approved tool use, and brand-safe output — prove every client-facing agent action stayed inside the agreed rules.
Overbooking, rate-parity, and comp gates — stop oversold rooms, off-parity rates, and over-limit comps before a booking confirms.
Every template defaults to shadow mode — it measures what it would catch without touching your live pipeline. Flip one rule to enforce when the evidence convinces you.
Each execution pattern is a recurring shape of risky action, with the policies that implement it already gathered. If you know the problem but not the platform, start here.
Cap what an agent can spend before the spend happens, not in next month's bill.
6 policies
Require the approval a deploy assumes it already has.
4 policies
Decide what leaves before it leaves, at the tool-call boundary.
8 policies
Decide what an agent may read, and what it may keep.
6 policies
Check delegated authority before the purchase order posts.
9 policies
Stop the payment that clears sanctions on paper but not in fact.
7 policies
Let support move fast without letting policy drift.
5 policies
Refuse the order that ships below your true cost.
10 policies
Stop the same last unit selling twice.
5 policies
Make deleting production a decision, not a command.
3 policies
Grant the narrowest scope that works, and expire it.
6 policies
Commit infrastructure budget deliberately, not by autoscale.
4 policies
Decide what reaches an external system before the request is made.
6 policies
Govern changes to the rules, not only actions under them.
6 policies
Check the run before it commits, not in the reconciliation.
3 policies