Gates the extension call a Vertex AI model wants to make, so an out-of-scope or unapproved tool never executes.
For: Teams running governed execution through the Vertex AI extension surface
Blocks an extension call outside the approved list for the project.
Blocks a call whose target falls outside the agent's declared scope.
Escalates when the call carries a requires-human-approval flag.
# Vertex AI Tool-Execution Gate
# Fork: list the extensions your project actually approves.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: vertex-ai-tool-execution-gate
surface: vertex_ai
standards: [SOC2-CC7.2, ISO27001-A.8.9]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
approved_extensions: [code_interpreter, vertex_ai_search, internal_lookup]
rules:
- name: approved_extension_check
when: "action == 'extension.execute'"
decision: |
BLOCK IF extension.id not in approved_extensions
ALLOW OTHERWISE
reason_code: extension_not_approved
- name: scope_containment
when: "action == 'extension.execute'"
decision: |
BLOCK IF outside_scope == true
ALLOW OTHERWISE
reason_code: call_outside_agent_scope
- name: human_approval_requirement
when: "action == 'extension.execute'"
decision: |
ESCALATE IF requires_human == true
ALLOW OTHERWISE
reason_code: call_requires_human_approval
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.