← Pipelines
Policies
Org-level rules that inject mandatory steps into every pipeline.
What policies do
A policy matches repos by file pattern and injects steps that teams cannot bypass. Security scanning on every repo with a lockfile. License checks on every repo with a Dockerfile. The org owner defines the rules; teams focus on their code.
Policy format
Policies live in the org-pipelines repo under policies/.
description: Security scan on all Node repos
enabled: true
match:
files:
- pnpm-lock.yaml
- package-lock.json
inject:
before:
- name: security-scan
use: trivy-scan
only: main
after: [] Policy fields
| Field | Description |
|---|---|
| description | Human-readable purpose of this policy. |
| enabled | Toggle the policy on or off. |
| match.files | Repo is matched if any of these files exist. |
| inject.before | Steps injected before the repo's own pipeline. |
| inject.after | Steps injected after the repo's own pipeline. |
| inject.before[].only | Branch filter for this step. Omit to run on all branches. |
Modes
Policies have two modes:
default— provides fallback steps. If a repo adds its own.gittan.yamlwith steps, the default policy’s steps are replaced.enforce— always included, cannot be overridden. Use for security-critical gates.
Scope
Policies can be defined at two levels:
- Org — in the
org-pipelinesrepo. Applies to all repos in the org. - Team — in a
{team-name}-pipelinesrepo. Applies only to that team's repos.