Never let an automation or agent move an opportunity above $1M into Closed Won without the approval chain.
For: RevOps and sales leadership on Salesforce with automated stage updates
Escalates a stage change to Closed Won on an opportunity above $1M until the approval chain signs.
Restrains a stage change made by an automation or agent rather than a named rep.
Blocks a close date set earlier than the current period.
# Salesforce Opportunity-Stage Guard
# Fork: set the value ceiling and the approver roles for your org.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: salesforce-opportunity-stage-guard
surface: salesforce
workflow_key: opportunity_stage_change
standards: [SOC2-CC8.1, ISO27001-A.5.15]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: high_value_stage_escalation
when: "action == 'opportunity.stage_change' AND stage_to == 'Closed Won'"
decision: |
ALLOW IF amount_usd < 1000000
ESCALATE IF approval_chain_complete == true
BLOCK OTHERWISE
reason_code: high_value_stage_change
- name: automated_actor_restraint
when: "action == 'opportunity.stage_change'"
decision: |
RESTRAIN IF actor.type in ['automation', 'agent']
ALLOW OTHERWISE
reason_code: stage_change_by_non_human
- name: backdated_close_block
when: "action == 'opportunity.stage_change'"
decision: |
BLOCK IF close_date < period.start
ALLOW OTHERWISE
reason_code: close_date_backdated
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.