Stops a purchase order releasing to an unapproved supplier or past the requester's authority limit.
For: Procurement and finance controls teams on SAP
Blocks a PO release to a supplier that is not on the approved master list.
Escalates a PO above the requester's delegated authority limit.
Restrains a release when the PO, receipt, and invoice do not reconcile.
# SAP Procurement PO Release Gate
# Fork: point supplier_master at your own approved-vendor source.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: sap-procurement-po-release-gate
surface: sap
workflow_key: purchase_order_release
standards: [SOC2-CC6.1, ISO27001-A.5.19]
defaults:
mode: shadow
emit_dossier: true
rules:
- name: approved_supplier_requirement
when: "action == 'po.release'"
decision: |
BLOCK IF supplier.id not in supplier_master.approved_ids
ALLOW OTHERWISE
reason_code: supplier_not_approved
- name: authority_ceiling
when: "action == 'po.release'"
decision: |
ESCALATE IF amount_usd > requester.authority_limit_usd
ALLOW OTHERWISE
reason_code: over_delegated_authority
- name: three_way_match_restraint
when: "action == 'invoice.post'"
decision: |
RESTRAIN IF three_way_match.reconciled == false
ALLOW OTHERWISE
reason_code: three_way_match_failed
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.