Skip to content
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Separation of duties

approval:
separationOfDuties:
enabled: true
rules:
- actorCannotApproveOwnAction: true
- initiatorCannotApprove: true

Example flow: an agent creates a pull request, a developer reviews, security approves, a release manager deploys; each step by a different human. The runtime rejects approvals that violate a rule and records the reason.

Normative text: Separation of duties.