Decision artifact
Policy as code expresses authorization rules in a machine-readable artifact that follows a controlled software lifecycle. It makes the effective rule reviewable, testable, versioned, deployable, and attributable. The source file is not the control by itself. The control includes policy inputs, evaluation semantics, distribution, enforcement, evidence, and recovery.
Separate policy from mechanism
State the intended permission before selecting syntax. Define subjects, resources, actions, context, decision results, and safe defaults. Keep policy administration separate from the mechanisms that collect attributes, decide, cache, and enforce. This separation lets reviewers detect a correct rule attached to the wrong resource or enforcer.
Change safely
Require review for sensitive changes. Validate schema and references, run positive and negative fixtures, compare the new decision set with the current set, stage the rollout, observe results, and retain a tested rollback. Record the source revision and compiled policy version with each decision.
Failure and residual risk
Valid syntax can encode unsafe intent. Tests can omit a resource class or stale context. Different evaluators can interpret policy differently. A successful deployment can leave stale caches or bypass paths. Emergency edits can outlive the incident. Policy code also exposes sensitive group, resource, and business logic if access to the repository is too broad.
Pomerium boundary
Pomerium Policy Language defines access to Pomerium routes. Teams can review and deploy this policy with the rest of their configuration. Pomerium does not replace application authorization for records, fields, transactions, or business actions. Those permissions need their own reviewed policy and evidence.
Evaluation checklist
- Does the policy name the protected resource and permitted action?
- Does missing or invalid context produce the safe result?
- Do tests cover allow, deny, conflict, indeterminate, and boundary cases?
- Can operators map a decision to an exact policy revision and input set?
- Can a rollout stop and roll back without leaving stale policy active?
