Skip to main content

Policy as Code

Treat access policy as a versioned, reviewed, tested, and observable decision artifact with controlled deployment.

Decision artifact

Policy as code expresses authorization rules in a machine-readable artifact that follows a controlled software lifecycle. It makes the effective rule reviewable, testable, versioned, deployable, and attributable. The source file is not the control by itself. The control includes policy inputs, evaluation semantics, distribution, enforcement, evidence, and recovery.

Separate policy from mechanism

State the intended permission before selecting syntax. Define subjects, resources, actions, context, decision results, and safe defaults. Keep policy administration separate from the mechanisms that collect attributes, decide, cache, and enforce. This separation lets reviewers detect a correct rule attached to the wrong resource or enforcer.

Change safely

Require review for sensitive changes. Validate schema and references, run positive and negative fixtures, compare the new decision set with the current set, stage the rollout, observe results, and retain a tested rollback. Record the source revision and compiled policy version with each decision.

Failure and residual risk

Valid syntax can encode unsafe intent. Tests can omit a resource class or stale context. Different evaluators can interpret policy differently. A successful deployment can leave stale caches or bypass paths. Emergency edits can outlive the incident. Policy code also exposes sensitive group, resource, and business logic if access to the repository is too broad.

Pomerium boundary

Pomerium Policy Language defines access to Pomerium routes. Teams can review and deploy this policy with the rest of their configuration. Pomerium does not replace application authorization for records, fields, transactions, or business actions. Those permissions need their own reviewed policy and evidence.

Evaluation checklist

  • Does the policy name the protected resource and permitted action?
  • Does missing or invalid context produce the safe result?
  • Do tests cover allow, deny, conflict, indeterminate, and boundary cases?
  • Can operators map a decision to an exact policy revision and input set?
  • Can a rollout stop and roll back without leaving stale policy active?

Sources and further reading

Keep learning

Authorization and Policy

Policy

In access control, a policy is a machine-enforceable set of rules that decides whether a subject can perform an action on a resource under stated conditions.

Learn this term
Authorization and PolicySecurity Operations and Risk

Authorization Decision Log

Record enough structured evidence to explain and test an access decision without storing credentials or excess personal data.

Learn this term

Get a Personalized Demo

Schedule a Call with a Pomerium Engineer

Get a Demo