Blocks unapproved OAuth grants and SaaS signups before anyone clicks through the terms.
For: IT procurement and security reviewing shadow-IT signups
Blocks an OAuth grant or SaaS signup for a vendor outside the approved catalog.
Escalates an OAuth grant requesting broader scopes than the catalog entry authorized.
Restrains procurement of a tool that processes data outside the allowed regions.
# ServiceNow Software Procurement Gate
# Fork: point approved_software_catalog at your own CMDB / vendor list.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: servicenow-software-procurement-gate
surface: servicenow
workflow_key: software_procurement
standards: [SOC2-CC6.1, ISO27001-A.5.19]
defaults:
mode: shadow
emit_dossier: true
allowed_regions: [EU, US]
rules:
- name: approved_catalog_requirement
when: "action in ['oauth.grant', 'saas.signup']"
decision: |
BLOCK IF vendor.id not in approved_software_catalog
ALLOW OTHERWISE
reason_code: unapproved_software_procurement
- name: scope_creep_escalation
when: "action == 'oauth.grant'"
decision: |
ESCALATE IF requested_scopes not subset_of catalog_entry.authorized_scopes
ALLOW OTHERWISE
reason_code: oauth_scope_exceeds_catalog
- name: data_residency_restraint
when: "action == 'saas.signup'"
decision: |
RESTRAIN IF vendor.processing_region not in allowed_regions
ALLOW OTHERWISE
reason_code: processing_region_not_allowed
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.