Same rollout everywhere we ship: GitHub Action, LangChain for Python and JavaScript, Azure API Management, Slack, Shopify. The gate records a signed Decision Dossier for every call, and no verdict blocks anything until you decide to enforce. One-line change to flip, reversible without uninstalling.
You don't have to wire every surface — start with the one whose audit you'd be asked about first. Tabs below swap the install snippet to that surface verbatim.
One step in any workflow YAML; the same binary on GitLab CI and Jenkins. Verdicts surface on the PR, the run summary and the step's outputs.
# .github/workflows/deploy.yml
- uses: decionis/govern@v2
with:
api-key: ${{ secrets.DECIONIS_API_KEY }}
tenant-id: ${{ vars.DECIONIS_TENANT_ID }}
action: production-deploy
mode: shadow # ← every verdict recorded; the step never fails
comment: "true" # ← the verdict + verify URL on the PR
Every gated call produces a signed Decision Dossier. No verdict blocks anything yet.
Each PR carries one Decionis comment, updated in place, with the verdict, the decision and dossier ids and the verify URL; the step's outputs (decision, dossier-id, intent-hash, outcome) feed later steps. The same dossier is in your Decionis audit log, filterable by the action type the step names.
/verify/decision-dossiers/<id>.One-line change. Reversible without uninstalling.
# .github/workflows/deploy.yml
- uses: decionis/govern@v2
with:
api-key: ${{ secrets.DECIONIS_API_KEY }}
tenant-id: ${{ vars.DECIONIS_TENANT_ID }}
action: production-deploy
- mode: shadow
+ mode: enforce # ← the command runs only on a claimed ALLOW
+ run: ./deploy.sh # ← through the gate or not at all
comment: "true"
Same dossier id, same verify URL, same audit log — the only difference is that blocked verdicts now actually hold the action. If a real workflow regresses, swap back to shadow: the rollback is the same one-line edit, in reverse.
What shadow measures is your execution authority gap: the actions that executed with no explicit authority in front of them — how many would have been held or blocked under your own policy, and what exposure passed through unevaluated. It is measured on your traffic, so the number is yours, not a benchmark.
Every dossier ID you record in shadow opens to a public verification page and unfurls with the OG verdict card in Slack / Teams / LinkedIn. Use them in the rollout review packet — the same signed artifact is the proof your CFO, your security reviewer, and your customer's auditor all want.
Which actions auto-clear, escalate, or block.
Who receives gray-zone actions and override reviews.
Which verdicts need policy tuning before enforcement.
The one-line change that returns the workflow to shadow.