Policy Card

Policy Card A workflow diagram generated by Archify. 01 / Owner 02 / Layer 01 Govern-as-Code 03 / Evidence EX / Blocked Author as code Evaluate at the gate Record verdict Policy owner · accountable · Owner › Author as code Policy owner accountable Policy card · versioned, in repo · Layer 01 Govern-as-Code › Author as code Policy card versioned, in repo Policy engine · evaluates the card · Layer 01 Govern-as-Code › Evaluate at the gate Policy engine evaluates the card Policy gate · allow / deny · Layer 01 Govern-as-Code › Evaluate at the gate Policy gate allow / deny Change proceeds · merged, deployed · Layer 01 Govern-as-Code › Record verdict Change proceeds merged, deployed Verdict record · rule · decision · time · Evidence › Record verdict Verdict record rule · decision · time Change blocked · outside policy · Blocked › Record verdict Change blocked outside policy record load evaluate deny allow authors record Legend Agent logic Policy Context / trace External system

A rule that executes

  • • One machine-readable card per obligation, versioned as a reviewable diff
  • • It encodes allow/deny logic, the failure mode and the clauses it maps to
  • • Stored in the repo with the system it governs

One gate, one verdict

  • • A policy engine evaluates the card at a single gate
  • • The change proceeds or is blocked outside the policy
  • • Each evaluation records a verdict against the change

First step

  • • Write one card for one obligation
  • • Wire it to one gate before adding more