Fairness, approval-chain, and offboarding gates — prove every hire, promotion, and termination cleared its checks.
For: People ops, talent, HR compliance
Restrains a hire or promotion that lacks a documented, bias-checked rationale.
Confirms the required approver chain signed off before the decision executes.
Confirms access and payroll are revoked when a termination event is received.
# HR & People Ops Pack
# Fork: the three gates from the hr starter pack, with your approver chain.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: hr-people-ops-pack
surface: workday
policy_pack_id: hr
standards: [SOC2-CC1.4, ISO27001-A.6.1]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: candidate_fairness_check
when: "action in ['hire.execute', 'promotion.execute']"
decision: |
RESTRAIN IF fairness_rationale_attached == false
ALLOW OTHERWISE
reason_code: fairness_rationale_missing
- name: approval_chain_gate
when: "action in ['hire.execute', 'promotion.execute', 'compensation.change']"
decision: |
ESCALATE IF approval_chain_complete == false
ALLOW OTHERWISE
reason_code: approval_chain_incomplete
- name: offboarding_guard
when: "event == 'worker.terminated'"
decision: |
RESTRAIN IF access_revoked == false OR payroll_stopped == false
ALLOW OTHERWISE
reason_code: offboarding_incomplete
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.