Separation of duties
approval: separationOfDuties: enabled: true rules: - actorCannotApproveOwnAction: true - initiatorCannotApprove: trueExample flow: an agent creates a pull request, a developer reviews, security approves, a release manager deploys; each step by a different human. The runtime rejects approvals that violate a rule and records the reason.
Normative text: Separation of duties.