Evidence ceiling E3Proof boundary

POLICY/1 · ENTERPRISE CONSTITUTION PROTOCOL

Companies need a machine-readable constitution, not another authorization silo.

POLICY/1 compiles approved governance sources into attributable PolicyIR, computes the normative closure for an action, fails HOLD on unresolved conflicts, scopes exceptions, propagates policy changes and proposes controls without self-awarding compliance.

Reference decision

ALLOW

The synthetic standard-risk model deployment is governed by a board permission and an independently ranked risk prohibition that only applies to HIGH risk. Precedence comes from an explicit institution-approved profile, not from POLICY/1 guessing legal hierarchy.

CONSTITUTION
sha256:f18373af14305abf2f18907b2c0554f2adcea001cde50973aaac2b5ac7ef87f1
ACTIVE RULES
POLICY70-DEPLOY
DECISION
ALLOW
OBLIGATIONS
AUDIT_LOG · FINALITY_OUTCOME_PROFILE
CORE LINES
25

Not another OPA/Cedar/AuthZEN

PORTABLE GOVERNANCE ABOVE ENFORCEMENT ENGINES

OPA and Cedar remain policy engines; AuthZEN standardizes PDP/PEP communication; LegalRuleML and ODRL provide normative/policy expression. POLICY/1 focuses on provenance-preserving enterprise compilation, conflict closure, exception lifecycle, change impact and cross-system policy debt.

01

Normative closure

Determine which institution-approved rules actually govern this action.

02

Conflict lattice

Unresolved same-authority conflicts become HOLD rather than an invented answer.

03

Exception escrow

Exceptions are attributable, scoped and expiring.

04

Change impact

A rule change exposes declared downstream controls, actions and resources needing reevaluation.

05

Control synthesis

Generate candidate control mappings without claiming they are approved or effective.

06

Policy debt

Measure obligations that remain unmapped or unenforced.

Public knowledge index

Search Finality Group

Protected, owner-only and legacy content is excluded.