Skip to main content

Cedar Policy

Generated Evaluation Status

This section is generated from the framework manifest and compatibility report. Do not edit it manually.

  • Framework ID: cedar-policy
  • Manifest: docs/external-frameworks/cedar-policy.json
  • Compatibility report: ./reports/cedar-policy.compatibility.json
  • Evidence class: SOURCE_REVIEWED
  • Independently reproducible: False
  • Comparative-testing claim allowed: False
  • Missing reproducibility gates: shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction
  • Evaluation result: COMPATIBILITY_EVIDENCE_ONLY
  • Cycle status: FIRST_FRAMEWORK_CYCLE_COMPLETE
  • Execution authority claim: False
  • Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
  • Posting source: generated compatibility report
  • Generated status is descriptive compatibility evidence only.

Generated Authored Analysis Boundary

This section is generated. Do not edit it manually.

  • Framework ID: cedar-policy
  • Framework name: Cedar Policy
  • Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
  • Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
  • Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
  • Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.

Generated Transition Mapping

This section is generated from the framework manifest. Do not edit it manually.

FieldGenerated Value
framework_identityCedar Policy
source_referencehttps://docs.cedarpolicy.com/
source_versionofficial documentation recorded
allowed_use_boundaryauthorization evidence only
claimsprincipal-action-resource-context policy evaluation
non_claimsno commit-time admissibility or inherited authority
input_artifact_typeauthorization request and policy
output_artifact_typeauthorization decision artifact
actor_or_authority_modelexternal authorization model; authority not inherited
evidence_modelofficial source plus bounded crosswalk
policy_or_rule_modelCedar policies
delegation_modelnot established by Cedar alone
decision_or_result_modelauthorization decision evidence
execution_authority_claimfalse
receipt_or_trace_modelmanifest and report references
reconstruction_modelsource and mapping reconstruct bounded relationship
SPE_overlapauthorization evidence may inform standing review
StegVerse_ecosystem_overlapauthority-boundary evidence
fail_closed_conditionsmissing source, mapping, or authority overclaim

Generated mapping is compatibility evidence only.

Generated Framework Metadata

This section is generated from the external-framework registry. Do not edit it manually.

  • Framework ID: cedar-policy
  • Name: Cedar Policy
  • Registry status: SOURCED-CROSSWALK-PROVISIONAL
  • Testbench state: SOURCE_RECORDED_CROSSWALK_PROVISIONAL
  • Manifest path: docs/external-frameworks/cedar-policy.json
  • Source reference: https://docs.cedarpolicy.com/
  • Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.

Evidence posture

evidence_class: SOURCE_REVIEWED
page_completeness: COMPLETE_WITH_EXTERNAL_GATES
runtime_observation: none attached
independent_reproduction: false
comparative_testing_claim_allowed: false
execution_authority_claim_allowed: false

Published scope

Cedar is an authorization policy language and evaluation model for deciding whether a principal may perform an action on a resource in context.

Canonical source: https://docs.cedarpolicy.com/

Source snapshot posture: official documentation is recorded, but no pinned Cedar release, policy set hash, entity store, request vector, evaluator configuration, raw response, or independent replay receipt is attached.

Native terms

Cedar termMeaning hereStegVerse relationship
PrincipalActor or identity making a request.Actor evidence; not current standing by itself.
ActionRequested operation.Requested action in a Commitment Candidate.
ResourceObject acted upon.Governed target requiring current scope.
ContextAdditional request facts.Evidence that must be current and attributable.
Authorization responsePermit or forbid decision.Policy evidence; not execution authority.

Relationship to admissibility

Cedar asks: Is this principal authorized for this action on this resource in this context?
StegVerse asks: May this transition bind consequence now under current authority, delegation, policy, evidence, and recoverability conditions?

Cedar authorization results can become policy and authority evidence for a Commitment Candidate. StegVerse still reconstructs current standing at the consequence boundary.

Observation boundary

No public Cedar execution or StegVerse interoperability observation is claimed.

shared test vector: missing
raw output: missing
timestamp: missing
runtime configuration: missing
source version or hash: missing
replay commands: missing
declared expected outcome: missing
independent reproduction: missing

StegVerse analysis

CriterionCurrent result
IdentityPrincipal identity is supplied to Cedar and must be established elsewhere.
AuthorityPermit does not establish current consequence-binding authority.
PolicyStrong overlap when the exact policy set and schema are pinned.
DelegationDelegation relationships require separate source and validity evidence.
EvidenceRequest, entities, schema, policy set, and response can form an inspectable packet.
ReplayabilityRequires pinned evaluator, schema, policy set, entities, and request.
ReconstructabilityPartial until all input and version provenance is retained.
Failure behaviorMissing entities, schema errors, evaluator errors, or ambiguous scope must fail closed.
InteroperabilityCedar response can enter a Commitment Candidate as non-authorizing authorization evidence.

Commit-time interoperability contract

transition_id
principal
action
resource
context
cedar_request
cedar_response
policy_set_reference
policy_set_hash
schema_reference
entity_store_reference
cedar_version
policy_reference
delegation_reference
evidence_references
execution_context
validity_window
source_timestamp

Failure classes

Failure classAppliesCurrent evidence posture
Semantic equivalence divergenceYesCedar permit/forbid is not StegVerse ALLOW/DENY.
Authority driftYesAuthority can change between evaluation and consequence.
Stale evidenceYesPrincipal, resource, context, and entity relationships can become stale.
Delegation leakageYesEntity relationships may overstate delegated scope.
Replay divergenceYesSchema, policy, entity, or evaluator changes may alter results.
Fail-open runtime errorYesEvaluation errors cannot become implicit permit.
Policy granularity gapYesAuthorization scope may be coarser than the governed transition.

Machine-readable companions

manifest: docs/external-frameworks/cedar-policy.json
compatibility report: docs/external-frameworks/reports/cedar-policy.compatibility.json
canonical registry: docs/external-frameworks/index.json
canonical union: static/external-frameworks/canonical-union-inventory.v1.json

Maintenance and challenge path

Maintenance owner: StegVerse-Labs/admissibility-wiki, External Frameworks audit surface.

A challenge must identify cedar-policy, the disputed claim or mapping, supporting source or artifact, and the requested evidence-class, completeness, or standing change. Evidence strength cannot increase without public inspectable artifacts.

Validation completion criteria

pinned Cedar implementation and version
pinned schema, policy set, and entity store
shared authorization requests
predeclared expected boundaries
raw responses and errors
timestamps and runtime configuration
replay commands
independent rerun receipt
non-claim language preserved

Benchmark relevance

authority_boundary, semantic_equivalence_boundary, commitment_boundary, interoperability_path

Non-claims

Cedar inclusion does not create certification, equivalence, execution authority, or StegVerse standing. Authorization evaluation is not independently reconstructed commit-time admissibility. This page does not claim live integration or general compatibility.

Next safe build target

Attach one pinned Cedar request packet containing schema, policies, entities, request, raw authorization response, expected StegVerse boundary, replay command, and independent rerun receipt.

This page reflects a bounded admissibility packet. Publication does not create standing. The reflected claim inherits only the standing reconstructable from referenced evidence, authority, and admissibility conditions.