Policy gate at the deploy step
Scorecard checks run as policy-as-code evaluation at every deployment attempt. If the service score falls below the configured threshold, the pipeline is blocked. The gate result is written to a tamper-evident audit record that includes each check score, the threshold, the policy version, and the identity of the requester.