Rule Cascade
Examples

Level cascade

An organisation baseline and a retail feature ruleset that extends it, tightens a limit and raises a severity - and what the result looks like.

Files: examples/contracts/acme-org-base.ruleset.yaml (acme.org.base@1.2.0) and examples/contracts/payments-transfer.ruleset.yaml (acme.payments.transfer@1.0.0).

metadata:
  id: acme.org.base
  version: 1.2.0
  title: Acme organisation-wide money movement rules
  owner: enterprise-risk

scope:
  - { level: enterprise, id: acme-group }
  - { level: organization, id: acme }

params:
  blockedCountries:
    type: stringList
    default: [KP, IR]
    description: ISO 3166-1 alpha-2 codes no transfer may be sent to.
    overridePolicy: locked
  maxTransferAmount:
    type: number
    default: 50000
    description: Largest single transfer without a risk acceptance.
    overridePolicy: tighten-only
    tightenDirection: lower

What a teller's 30,000 transfer returns (one finding shown). The limit is the tightened 25000, and source names the level that defined the rule:

{
  "rule": "org.transfer.amount-limit",
  "code": "ORG-TRF-002",
  "severity": "error",
  "message": "Amount exceeds the single-transfer limit of 25000.",
  "fields": ["/amount"],
  "location": { "component": "amount-panel" },
  "blocking": true,
  "status": "open",
  "resolution": "accept-risk",
  "acceptableBy": ["risk-officer"],
  "source": "acme.org.base@1.2.0"
}

The golden tests of the feature ruleset pin this down: "over the tightened retail limit is denied for an ordinary user" and "a risk officer can accept the limit breach with a justification".

What the policies refuse, and how to build your own chain: Multi-level inheritance and overrides.

Source: site/content/docs/examples/level-cascade.mdx