Normative closure
Determine which institution-approved rules actually govern this action.
POLICY/1 · ENTERPRISE CONSTITUTION PROTOCOL
POLICY/1 compiles approved governance sources into attributable PolicyIR, computes the normative closure for an action, fails HOLD on unresolved conflicts, scopes exceptions, propagates policy changes and proposes controls without self-awarding compliance.
Reference decision
The synthetic standard-risk model deployment is governed by a board permission and an independently ranked risk prohibition that only applies to HIGH risk. Precedence comes from an explicit institution-approved profile, not from POLICY/1 guessing legal hierarchy.
Not another OPA/Cedar/AuthZEN
OPA and Cedar remain policy engines; AuthZEN standardizes PDP/PEP communication; LegalRuleML and ODRL provide normative/policy expression. POLICY/1 focuses on provenance-preserving enterprise compilation, conflict closure, exception lifecycle, change impact and cross-system policy debt.
Determine which institution-approved rules actually govern this action.
Unresolved same-authority conflicts become HOLD rather than an invented answer.
Exceptions are attributable, scoped and expiring.
A rule change exposes declared downstream controls, actions and resources needing reevaluation.
Generate candidate control mappings without claiming they are approved or effective.
Measure obligations that remain unmapped or unenforced.