Velocity, sanctions, and treasury movement controls — automated proof of every KYC, AML, payout, and limit decision.
For: Neobanks, payfacs, crypto ops
Flags or blocks high-value movement based on amount and risk posture.
Requires fresh sanctions evidence before an international payout executes.
Requires dual approval before corporate funds move above the threshold.
# Fintech Starter Pack
# Fork: the three gates from the fintech starter pack, with your thresholds.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: fintech-starter-pack
surface: sdk
policy_pack_id: fintech
standards: [SOC2-CC8.1, ISO27001-A.8.34]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: tiered_velocity_gate
when: "action == 'payout.execute'"
decision: |
ALLOW IF amount_usd < 10000 AND risk_posture == 'standard'
ESCALATE IF amount_usd < 250000
BLOCK OTHERWISE
reason_code: velocity_tier_exceeded
- name: cross_border_sanction_check
when: "action == 'payout.execute' AND cross_border == true"
decision: |
BLOCK IF sanctions_evidence == null
ESCALATE IF sanctions_evidence.age_hours > 24
ALLOW OTHERWISE
reason_code: sanctions_evidence_missing
- name: treasury_lock
when: "action == 'treasury.move'"
decision: |
BLOCK IF amount_usd >= 250000 AND approvals.count < 2
ESCALATE IF amount_usd >= 10000
ALLOW OTHERWISE
reason_code: treasury_dual_approval_required
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.