Open Policy Agent
Generated Evaluation Status
This section is generated from the framework manifest and compatibility report. Do not edit it manually.
- Framework ID:
open-policy-agent - Manifest:
docs/external-frameworks/open-policy-agent.json - Compatibility report:
./reports/open-policy-agent.compatibility.json - Evidence class:
SOURCE_REVIEWED - Independently reproducible:
False - Comparative-testing claim allowed:
False - Missing reproducibility gates:
shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction - Evaluation result:
COMPATIBILITY_EVIDENCE_ONLY - Cycle status:
FIRST_FRAMEWORK_CYCLE_COMPLETE - Execution authority claim:
False - Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
- Posting source: generated compatibility report
- Generated status is descriptive compatibility evidence only.
Generated Authored Analysis Boundary
This section is generated. Do not edit it manually.
- Framework ID:
open-policy-agent - Framework name:
Open Policy Agent - Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
- Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
- Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
- Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.
Generated Transition Mapping
This section is generated from the framework manifest. Do not edit it manually.
| Field | Generated Value |
|---|---|
framework_identity | Open Policy Agent |
source_reference | https://www.openpolicyagent.org/docs/latest/ |
source_version | official documentation recorded |
allowed_use_boundary | policy-decision evidence only |
claims | structured policy evaluation |
non_claims | no admissibility proof or execution authority |
input_artifact_type | structured input and policy |
output_artifact_type | policy decision artifact |
actor_or_authority_model | external policy engine; authority not inherited |
evidence_model | official source plus bounded crosswalk |
policy_or_rule_model | policy rules |
delegation_model | not established by OPA |
decision_or_result_model | policy decision evidence |
execution_authority_claim | false |
receipt_or_trace_model | manifest and report references |
reconstruction_model | source and mapping reconstruct the bounded relationship |
SPE_overlap | policy evidence may inform standing review |
StegVerse_ecosystem_overlap | commitment-boundary policy evidence |
fail_closed_conditions | missing source, mapping, or authority overclaim |
Generated mapping is compatibility evidence only.
Generated Framework Metadata
This section is generated from the external-framework registry. Do not edit it manually.
- Framework ID:
open-policy-agent - Name:
Open Policy Agent - Registry status:
SOURCED-CROSSWALK-PROVISIONAL - Testbench state:
SOURCE_RECORDED_CROSSWALK_PROVISIONAL - Manifest path:
docs/external-frameworks/open-policy-agent.json - Source reference:
https://www.openpolicyagent.org/docs/latest/ - Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.
Evidence posture
evidence_class: SOURCE_REVIEWED
page_completeness: COMPLETE_WITH_EXTERNAL_GATES
runtime_observation: none attached
independent_reproduction: false
comparative_testing_claim_allowed: false
execution_authority_claim_allowed: false
Published scope
Open Policy Agent is a general-purpose policy engine that evaluates structured input against policy and produces policy decisions.
Canonical source: https://www.openpolicyagent.org/docs/latest/
Source snapshot posture: official documentation is recorded, but no pinned OPA release, policy bundle hash, runtime configuration, raw decision log, or independent replay receipt is attached to this page.
Native terms
| OPA term | Meaning here | StegVerse relationship |
|---|---|---|
| Input | Structured facts supplied for evaluation. | Evidence input; not standing by itself. |
| Policy | Rego rules and data used to evaluate input. | Policy reference that must remain current and scoped. |
| Decision | OPA evaluation output. | Commitment Candidate evidence; not execution authority. |
| Bundle | Deployable policy and data package. | Versioned source artifact requiring hash and custody evidence. |
Relationship to admissibility
OPA asks: What result follows from this input, policy, and data?
StegVerse asks: May this transition bind consequence at commit time under current identity, authority, policy, delegation, and evidence?
OPA can contribute a policy-decision artifact to a governed transition path. That decision is evidence about policy evaluation; it does not establish that the actor has current authority, that delegation remains valid, or that consequence may bind now.
OPA input + policy -> policy decision
policy decision -> Commitment Candidate evidence
SPE -> reconstruct current standing
SPE result -> ALLOW / DENY / FAIL-CLOSED
Observation boundary
No public StegVerse runtime observation is claimed on this page.
shared test vector: missing
raw output: missing
timestamp: missing
runtime configuration: missing
source version or hash: missing
replay commands: missing
declared expected outcome: missing
independent reproduction: missing
The compatibility report must remain SOURCE_REVIEWED until these fields are public and inspectable.
StegVerse analysis
| Criterion | Current result |
|---|---|
| Identity | OPA evaluates supplied attributes; it does not independently establish actor identity. |
| Authority | An allow decision does not establish current consequence-binding authority. |
| Policy | Strong overlap: OPA can produce inspectable policy decisions when policy identity is pinned. |
| Delegation | Delegation must be supplied and reconstructed separately. |
| Evidence | Decision logs can become evidence when inputs, policy bundle, version, and output are retained. |
| Replayability | Possible only with pinned engine, bundle, data, input, and configuration. |
| Reconstructability | Partial until complete input and decision provenance are retained. |
| Failure behavior | Integration must fail closed on missing policy, undefined result, stale bundle, or evaluation error. |
| Interoperability | OPA output can route into a Commitment Candidate as non-authorizing policy evidence. |
Commit-time interoperability contract
Minimum OPA-specific fields:
transition_id
actor
requested_action
target_system
opa_input
opa_decision
opa_query
policy_bundle_reference
policy_bundle_hash
opa_version
data_reference
decision_log_reference
policy_reference
delegation_reference
evidence_references
execution_context
validity_window
source_timestamp
Failure classes
| Failure class | Applies | Current evidence posture |
|---|---|---|
| Semantic equivalence divergence | Yes | OPA allow/deny must not be equated with StegVerse ALLOW/DENY. |
| Authority drift | Yes | Authority can change after policy evaluation. |
| Stale evidence | Yes | Policy bundles and input facts can become stale. |
| Delegation leakage | Yes | Supplied roles or claims may exceed current delegation. |
| Replay divergence | Yes | Different engine, bundle, data, or configuration can change output. |
| Fail-open runtime error | Yes | Undefined or errored evaluations must not authorize execution. |
| Source-claim mismatch | Yes | Documentation or policy labels may not match the deployed artifact. |
Machine-readable companions
manifest: docs/external-frameworks/open-policy-agent.json
compatibility report: docs/external-frameworks/reports/open-policy-agent.compatibility.json
canonical registry: docs/external-frameworks/index.json
canonical union: static/external-frameworks/canonical-union-inventory.v1.json
Maintenance and challenge path
Maintenance owner: StegVerse-Labs/admissibility-wiki, External Frameworks audit surface.
A challenge must identify the framework ID open-policy-agent, the disputed field or claim, the source or artifact supporting the correction, and whether the requested change affects source posture, evidence class, page completeness, or standing. No challenge may increase evidence strength without corresponding public artifacts.
Validation completion criteria
pinned OPA release or binary identity
pinned policy bundle and data hashes
shared input vectors
predeclared expected boundaries
raw decision outputs and errors
timestamps and runtime configuration
replay commands
independent rerun receipt
non-claim language preserved
Benchmark relevance
commitment_boundary, authority_boundary, unknown_trajectory_boundary, interoperability_path
Non-claims
OPA inclusion is not certification, equivalence, admissibility proof, or StegVerse standing. A policy allow result does not independently authorize consequence binding. This page does not claim live integration, production deployment, or general compatibility.
Next safe build target
Attach one pinned OPA decision bundle with input, Rego and data hashes, raw output, runtime configuration, expected StegVerse boundary, replay command, and an independent rerun receipt.
This page reflects a bounded admissibility packet. Publication does not create standing. The reflected claim inherits only the standing reconstructable from the referenced evidence, authority, and admissibility conditions.