Examples
Level cascade
An organisation baseline and a retail feature ruleset that extends it, tightens a limit and raises a severity - and what the result looks like.
Files: examples/contracts/acme-org-base.ruleset.yaml
(acme.org.base@1.2.0) and
examples/contracts/payments-transfer.ruleset.yaml
(acme.payments.transfer@1.0.0).
metadata:
id: acme.org.base
version: 1.2.0
title: Acme organisation-wide money movement rules
owner: enterprise-risk
scope:
- { level: enterprise, id: acme-group }
- { level: organization, id: acme }
params:
blockedCountries:
type: stringList
default: [KP, IR]
description: ISO 3166-1 alpha-2 codes no transfer may be sent to.
overridePolicy: locked
maxTransferAmount:
type: number
default: 50000
description: Largest single transfer without a risk acceptance.
overridePolicy: tighten-only
tightenDirection: lowerWhat a teller's 30,000 transfer returns (one finding shown). The limit is the tightened 25000, and
source names the level that defined the rule:
{
"rule": "org.transfer.amount-limit",
"code": "ORG-TRF-002",
"severity": "error",
"message": "Amount exceeds the single-transfer limit of 25000.",
"fields": ["/amount"],
"location": { "component": "amount-panel" },
"blocking": true,
"status": "open",
"resolution": "accept-risk",
"acceptableBy": ["risk-officer"],
"source": "acme.org.base@1.2.0"
}The golden tests of the feature ruleset pin this down: "over the tightened retail limit is denied for an ordinary user" and "a risk officer can accept the limit breach with a justification".
What the policies refuse, and how to build your own chain: Multi-level inheritance and overrides.