Approval-Gated Destructive Automation Policy Engine Prompt
Design a policy engine (OPA/Rego or equivalent) that intercepts automated actions at runtime and enforces approval, blast-radius, and time-window rules before destructive operations run.
- Target user
- Platform and security engineers governing automation at scale
- Difficulty
- Advanced
- Tools
- Claude, ChatGPT
The prompt
You are a senior platform-security engineer who designs runtime policy enforcement for automation systems. I will provide: - The automation actions to govern and which are destructive (delete, scale-to-zero, restart, drop) - The execution paths (CI/CD, orchestrator, ChatOps, scheduled jobs) that should be gated - Existing identity/approval tooling and change-window rules - Compliance requirements that must be auditable Your job: 1. **Classify actions** — define a taxonomy and tag each action with risk level and reversibility. 2. **Author policies** — write policy-as-code rules (e.g. Rego) that allow, deny, or require-approval per action, actor, environment, and time window. 3. **Approval flow** — design the human-approval handshake (who, quorum, timeout) and how a gated action resumes after approval. 4. **Blast-radius limits** — encode caps (max nodes, max % of fleet) the policy enforces independent of the caller. 5. **Break-glass** — define an emergency override with mandatory logging and post-hoc review. 6. **Enforcement point** — describe where the engine sits (admission webhook, orchestrator hook, gateway) so it cannot be bypassed. 7. **Audit** — specify the immutable decision log and the compliance report it produces. Output as: (a) the action taxonomy, (b) annotated policy rules, (c) the approval and break-glass flows, (d) the audit/report schema. Default-deny destructive actions outside approved windows; require explicit approval and ensure the policy engine cannot be silently bypassed by any execution path.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
Automated Compliance Check Pipeline Prompt
Design an automated continuous-compliance pipeline — policy-as-code controls, evidence collection, and auto-remediation of low-risk violations — mapped to a framework like CIS, SOC 2, or PCI.
-
Self-Service Automation Catalog Portal Design Prompt
Design a self-service catalog that lets engineers safely run curated automation jobs on demand, with parameter validation, RBAC, approvals for risky actions, and an audit trail, without handing out raw runbook access.
-
Human-in-the-Loop Approval Authority Design Prompt
Design the decision-authority model for human-in-the-loop automation — who may approve which action tier, when two-person review or quorum is required, how approvers get the context to decide well, and how break-glass and timeouts work without weakening the controls.
-
Read-Only-by-Default Automation Promotion Prompt
Design a maturity model that ships every new automation in read-only/observe-only mode first, then promotes it through suggest, gated-act, and finally auto-act tiers only after it earns trust with evidence — so nothing changes production state on day one.
More Automation prompts & error guides
Browse every Automation prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.