Approval flow
# Example: a reusable policy that requires a release manager for production deployments.apiVersion: awp.agenticworkflowprotocol.org/v1alpha1kind: Policy
metadata: name: no-production-autonomy version: 1.0.0 owner: team: platform-governance
spec: rules: - id: deploy-needs-release-manager when: action: production.deploy effect: requireApproval approval: approvers: - role: release-manager
- id: no-merge-in-production when: action: git.merge environment.name: production effect: requireApproval approval: approvers: - role: release-manager - role: security-reviewer minApprovals: 2The first rule makes every production.deploy wait for a release manager. The second requires two distinct approvers, one release manager and one security reviewer, for merges in production. Combine it with separation of duties:
approval: separationOfDuties: enabled: true rules: - actorCannotApproveOwnAction: trueSee Human approval and Separation of duties.