The Enterprise Policy Engine converts risk findings and business controls into one explainable action.
Policy v0 and its response contract are under review for the controlled pilot. Persisted tenant configuration, version history, approval workflows, and immutable decision audit remain 30-day platform work.
Decision semantics
Explainability contract
Return the policy ID, version, and each matched rule with the decision:
Precedence and safety
- Apply
BLOCK before REVIEW, and REVIEW before ALLOW.
- Return
ALLOW only when the policy is valid and no stronger rule matches.
- Fail closed to
REVIEW or BLOCK when providers fail, policy versions are invalid, or mandatory evidence is missing.
- Bind the decision record to the policy version, checked intent, evidence, timestamps, and final action.
- Display decisions in the browser. Keep authoritative risk and policy logic on the backend.