Skip to content

Support engine-enforced restricted policy operands #265

Description

@rlippmann

Summary

Add an Engine-level mechanism for restricting which policy operands are admissible.

The restriction should be authoritative in core, not merely an acquisition hint for Directive Drafter or an integration-specific validator.

Motivation

Some enforcement points need a finite policy vocabulary. For example, an agent/runtime integration may want to permit only a bounded set of policy operands that the host can actually enforce.

If only Directive Drafter is constrained, the restriction is advisory: another caller could still submit a canonical directive using an arbitrary operand and Engine would accept it. Engine therefore needs to enforce the operand domain itself.

Architectural direction

  • Attach/configure the allowed policy operand domain on an Engine.
  • Treat the restriction as Engine configuration rather than ordinary mutable authoritative state.
  • Enforce the restriction on every directive application path.
  • Keep premise handling out of scope; this is specifically about policy operands.
  • Directive Drafter may later consume the same configured operand set for constrained drafting, but Engine remains authoritative.
  • Integrations choose the operand domain appropriate to their enforcement point.

Deferred design questions

Do not resolve these as part of the initial architectural decision unless needed:

  • exact public API shape;
  • checkpoint/import compatibility semantics;
  • compound policy expressions such as and / or;
  • interaction with proposed partial-match behavior;
  • quoting/escaping for operand text that may overlap grammar operators.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions