Policies

Control who can perform an action on an exact Constal Resource and constrain the operation that is allowed.

A Policy evaluates normalized identity, an action, an exact Constal Resource Name, and bounded request context. Authorization is deny by default, explicit deny wins, and scopes can narrow existing grants but cannot manufacture authority. Policies can allow, deny, require approval, substitute safe values, constrain arguments or context, and grant short-lived capabilities.

Policies are ordinary versioned Resources deployed as deterministic executable packages. Each package manifest selects exactly one authorization-target kind and zero, one, or many targets of that kind with the shared label-selector syntax. Targets include managed Resources and platform addresses such as sessions, bindings, and deployments. There is no public declarative Policy type. Runs pin the effective Policy hashes accepted at admission so replay does not silently gain new authority when a current Policy changes.

Where Policies apply

BoundaryExamples
Platform APIRead, create, update, control, export, or deploy actions
Agent executionStart a Run, call a model, use a Tool, commit or deliver a result
Resource invocationExact Resource, operation, arguments, effect, and Credential use
Channel ingressAuthenticated principal, customer mapping, target, and dispatch
Runtime controlResolve a wait, steer, pause, rebind, truncate, or cancel

Choose an interface

InterfaceUse it for
ConsoleReviewing deployed Policies, attachments, and decisions
SDKAuthoring deterministic executable Policy behavior
CLIDeploying packages and evaluating exact test requests
Platform APIPolicy-aware administration and scoped assignments

Use Author a Policy to build and test deterministic behavior. Use Govern Resource usage for typed controls and hard limits. Use Operate Policies to evaluate, select, version, and inspect effective decisions.