Skip to content
AWP v1alpha1 (draft)
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Approval flow

no-production-autonomy.policy.yaml
# Example: a reusable policy that requires a release manager for production deployments.
apiVersion: awp.agenticworkflowprotocol.org/v1alpha1
kind: Policy
metadata:
name: no-production-autonomy
version: 1.0.0
owner:
team: platform-governance
spec:
rules:
- id: deploy-needs-release-manager
when:
action: production.deploy
effect: requireApproval
approval:
approvers:
- role: release-manager
- id: no-merge-in-production
when:
action: git.merge
environment.name: production
effect: requireApproval
approval:
approvers:
- role: release-manager
- role: security-reviewer
minApprovals: 2

The first rule makes every production.deploy wait for a release manager. The second requires two distinct approvers, one release manager and one security reviewer, for merges in production. Combine it with separation of duties:

approval:
separationOfDuties:
enabled: true
rules:
- actorCannotApproveOwnAction: true

See Human approval and Separation of duties.