Call the evaluate endpoint from an HTTP Request node and branch the workflow on the verdict before the write step runs.
For: Teams self-hosting n8n workflows that write to production systems
Escalates a write to a production system when the payload exceeds the threshold.
Restrains the workflow when the gate cannot be reached, instead of writing blind.
Blocks a workflow run triggered by an actor with no authority for the action.
# n8n HTTP-Node Execution Gate
# Fork: POST the canonical payload from an HTTP Request node, then use an IF
# node on the returned verdict to branch before the protected write.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: n8n-http-node-execution-gate
surface: n8n
workflow_key: workflow_write_gate
standards: [SOC2-CC8.1, ISO27001-A.8.32]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
rules:
- name: write_step_gate
when: "step.writes_production == true"
decision: |
ALLOW IF amount_usd < 1000
ESCALATE OTHERWISE
reason_code: production_write_over_threshold
- name: gate_outage_restraint
when: "gate.reachable == false"
decision: |
RESTRAIN IF always
reason_code: gate_unreachable_fail_closed
- name: actor_authority_check
when: "always"
decision: |
BLOCK IF actor.authority_scope not contains action
ALLOW OTHERWISE
reason_code: actor_lacks_authority
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.