How do I connect CAF to a decision flow?
Add CAF as a connection in your workspace authenticating with OAuth 2.0 client credentials, with the credentials your own contract issued — ArboRule calls the provider as you, and never holds a contract on your behalf. Once the connection exists, any flow in the workspace can place a Connection node and choose one of its operations. The credentials live on the connection, not in the flow, so a policy owner can use CAF in a decision without ever seeing the secret.
Can I test CAF without touching production?
CAF exposes one host for both environments, so there is no separate sandbox to point at. Test runs still execute in Sandbox and are recorded separately in decision history, but the call goes to the same place as production — so guard it with your own test credentials, rate limits, or data.
What can a flow call on CAF?
2 operations: “Run a verification (create a transaction)”, “Read a verification's result”. Each one is a step you place on the canvas and map into the fields your rules read, and most flows start with “Run a verification (create a transaction)”. The list comes from the same manifest the engine uses to make the call, so this page cannot describe an operation the product does not have.
Where in a decision should CAF be called?
An identity check gates everything downstream — a score computed against an unverified identity is a score about nobody. These calls sit near the top of a flow, with the branch for a partial or failed match written explicitly rather than left as an exception.