The starting policy for any point of execution: risk band, hard rules, and a signed dossier on every verdict.
For: Engineers wiring the gate into their own service before the action commits
Allows below the escalation threshold, escalates in the middle band, blocks above.
Hard rules win over the score — a restricted subject blocks regardless of band.
Restrains the action when the gate cannot be reached, so nothing commits unevaluated.
# Universal Action Gate Baseline
# Fork: this is the neutral starting shape. Replace risk_field and thresholds
# with the signal your own payload actually carries.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: sdk-universal-action-gate-baseline
surface: sdk
standards: [SOC2-CC8.1, ISO27001-A.8.32]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
risk_field: risk_score
rules:
- name: risk_band_routing
when: "always"
decision: |
ALLOW IF risk_score < 60
ESCALATE IF risk_score < 85
BLOCK OTHERWISE
reason_code: risk_score_over_threshold
- name: hard_rule_precedence
when: "always"
decision: |
BLOCK IF restricted == true
ESCALATE IF requires_human_approval == true
ALLOW OTHERWISE
reason_code: hard_rule_matched
- name: fail_closed_on_outage
when: "gate.reachable == false"
decision: |
RESTRAIN IF always
reason_code: gate_unreachable_fail_closed
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.