Privileged-access and production-change controls for ServiceNow ITSM — proving every change followed the approved path.
For: Platform and security leads at health-tech and regulated orgs
Blocks production access for roles without administrative scope.
Allows changes only inside scheduled maintenance windows or with lead approval.
Restrains a change request until linked Jira / CAB evidence is present.
# HIPAA-Grade Access Change Gate
# Fork: tune roles, windows, and evidence sources to your environment.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: hipaa-grade-access-change
surface: servicenow
standards: [HIPAA-164.312, SOC2-CC6.2, ISO27001-A.5.18]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: role_scope_enforcement
when: "request == 'access.prod_db'"
decision: |
APPROVE IF actor.role == 'Lead' OR actor.role in admin_scope
BLOCK OTHERWISE
reason_code: role_lacks_admin_scope
- name: maintenance_window_gate
when: "change.type == 'production'"
decision: |
APPROVE IF window == 'scheduled_maintenance' OR approver.role == 'Lead'
ESCALATE OTHERWISE
reason_code: outside_maintenance_window
- name: evidence_completeness
when: "change.type == 'production'"
decision: |
RESTRAIN IF change.jira_evidence == null
ALLOW OTHERWISE
reason_code: cab_evidence_missing
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.