Stops a viral-spike order releasing on stock you do not have, or on a creator-commission stack that breaks margin.
For: TikTok Shop sellers running creator campaigns and flash promos
Blocks releasing fulfillment for units the system of record does not hold.
Blocks an order whose margin, after platform fee and creator commission, falls under the floor.
Restrains releases once a flash promo exceeds the units-per-minute ceiling, pending a human check.
# TikTok Shop Fulfillment Circuit Breaker
# Fork: set commission and velocity ceilings for your campaigns.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: tiktok-shop-fulfillment-breaker
surface: tiktok_shop
workflow_key: fulfillment_release
standards: [SOC2-CC8.1, ISO27001-A.8.34]
defaults:
mode: shadow
emit_dossier: true
margin_floor_pct: 10
velocity_ceiling_units_per_minute: 40
rules:
- name: spike_oversell_gate
when: "action == 'fulfillment.release'"
decision: |
BLOCK IF units_ordered > units_available
ALLOW OTHERWISE
reason_code: oversold_inventory
- name: creator_commission_margin_check
when: "action == 'fulfillment.release'"
decision: |
BLOCK IF (order.total - order.cost_basis - fees.platform - fees.creator_commission) / order.total < margin_floor_pct / 100
ALLOW OTHERWISE
reason_code: commission_adjusted_margin_below_floor
- name: flash_promo_velocity_restraint
when: "action == 'fulfillment.release' AND promo.is_flash == true"
decision: |
RESTRAIN IF promo.units_per_minute > velocity_ceiling_units_per_minute
ALLOW OTHERWISE
reason_code: flash_promo_velocity_exceeded
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.