Policies

Declarative rules for what an action needs before it can run.

A policy tells the gate what an action needs before it can run. Policies are declarative and deterministic: the same state always gives the same result.

What a policy contains

PartExample
Actionrelease_payment
Required stateclaim.amount and claim.approver, active and not in conflict
ConstraintsAmount at or below $10,000 without approval
ApprovalClaims Ops Lead above the threshold
Effect on breachBlock, or warn
Source controlOR-15 Human approval above payment thresholds (CPS 230)
policy: payments.threshold
version: 3
action: release_payment
requires:
  - key: claim.amount
    status: active
    no_open_conflict: true
  - key: claim.approver
    when: claim.amount > 10000
approval:
  above: 10000
  role: claims_ops_lead
on_breach: block
control: OR-15

The default policy

Changing a policy

Policies are versioned. A change creates a new version with an approval trail, and every decision records which version it used.

Last reviewed October 2026Suggest a change