Temporary admin rights get a timed dossier and a revocation trail — so the grant expires whether or not anyone remembers.
For: IT and security teams granting temporary elevated access
Blocks a temporary-admin grant requested for longer than the maximum window.
Escalates a grant with no scheduled revocation time attached.
Restrains a repeat grant to a requester who already holds an unexpired elevated role.
# ServiceNow Just-In-Time Access
# Fork: set max_window_hours to the shortest window your teams can work in.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: servicenow-just-in-time-access
surface: servicenow
workflow_key: temporary_admin_access
standards: [SOC2-CC6.2, ISO27001-A.5.18]
defaults:
mode: shadow
emit_dossier: true
max_window_hours: 8
rules:
- name: window_ceiling
when: "request == 'access.temporary_admin'"
decision: |
BLOCK IF requested_duration_hours > max_window_hours
ALLOW OTHERWISE
reason_code: jit_window_too_long
- name: revocation_requirement
when: "request == 'access.temporary_admin'"
decision: |
ESCALATE IF revocation_scheduled_at == null
ALLOW OTHERWISE
reason_code: no_scheduled_revocation
- name: standing_access_restraint
when: "request == 'access.temporary_admin'"
decision: |
RESTRAIN IF requester.has_unexpired_elevated_role == true
ALLOW OTHERWISE
reason_code: elevated_role_already_held
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.