One example I can think of is 1. Compile to cdktf 2. Scan with policy as code tool (checkov/OPA/KICKS/ other) 3. If scan step is passing then deploy with wing