Never discount below margin. Holds a WooCommerce checkout whose net margin would breach the encoded floor.
For: WooCommerce store owners running promotions and dynamic pricing
Blocks any order whose net margin would breach the encoded floor.
Stops unauthorized or cascading discount stacking at checkout.
Escalates an order where free shipping pushes the landed margin under the floor even though the item margin passes.
# WooCommerce Margin Floor Guard
# Fork: replace margin_floor_pct with your own cost basis and floor.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: woocommerce-margin-floor-guard
surface: woocommerce
workflow_key: checkout_margin_guard
standards: [SOC2-CC8.1, ISO27001-A.8.34]
defaults:
mode: shadow
emit_dossier: true
margin_floor_pct: 12
rules:
- name: margin_floor
when: "action == 'checkout.commit'"
decision: |
BLOCK IF order.net_margin_pct < margin_floor_pct
ALLOW OTHERWISE
reason_code: below_margin_floor
- name: coupon_stacking_ceiling
when: "action == 'checkout.apply_discount'"
decision: |
BLOCK IF coupons.count > 1 AND combined_discount_pct > 30
ESCALATE IF coupons.count > 1
ALLOW OTHERWISE
reason_code: unauthorized_coupon_stacking
- name: shipping_subsidy_check
when: "action == 'checkout.commit'"
decision: |
ESCALATE IF order.landed_margin_pct < margin_floor_pct
ALLOW OTHERWISE
reason_code: shipping_subsidy_erodes_margin
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.