Skip to main content

Open Policy Agent

Generated Evaluation Status

This section is generated from the framework manifest and compatibility report. Do not edit it manually.

  • Framework ID: open-policy-agent
  • Manifest: docs/external-frameworks/open-policy-agent.json
  • Compatibility report: ./reports/open-policy-agent.compatibility.json
  • Evidence class: SOURCE_REVIEWED
  • Independently reproducible: False
  • Comparative-testing claim allowed: False
  • Missing reproducibility gates: shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction
  • Evaluation result: COMPATIBILITY_EVIDENCE_ONLY
  • Cycle status: FIRST_FRAMEWORK_CYCLE_COMPLETE
  • Execution authority claim: False
  • Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
  • Posting source: generated compatibility report
  • Generated status is descriptive compatibility evidence only.

Generated Authored Analysis Boundary

This section is generated. Do not edit it manually.

  • Framework ID: open-policy-agent
  • Framework name: Open Policy Agent
  • Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
  • Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
  • Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
  • Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.

Generated Transition Mapping

This section is generated from the framework manifest. Do not edit it manually.

FieldGenerated Value
framework_identityOpen Policy Agent
source_referencehttps://www.openpolicyagent.org/docs/latest/
source_versionofficial documentation recorded
allowed_use_boundarypolicy-decision evidence only
claimsstructured policy evaluation
non_claimsno admissibility proof or execution authority
input_artifact_typestructured input and policy
output_artifact_typepolicy decision artifact
actor_or_authority_modelexternal policy engine; authority not inherited
evidence_modelofficial source plus bounded crosswalk
policy_or_rule_modelpolicy rules
delegation_modelnot established by OPA
decision_or_result_modelpolicy decision evidence
execution_authority_claimfalse
receipt_or_trace_modelmanifest and report references
reconstruction_modelsource and mapping reconstruct the bounded relationship
SPE_overlappolicy evidence may inform standing review
StegVerse_ecosystem_overlapcommitment-boundary policy evidence
fail_closed_conditionsmissing source, mapping, or authority overclaim

Generated mapping is compatibility evidence only.

Generated Framework Metadata

This section is generated from the external-framework registry. Do not edit it manually.

  • Framework ID: open-policy-agent
  • Name: Open Policy Agent
  • Registry status: SOURCED-CROSSWALK-PROVISIONAL
  • Testbench state: SOURCE_RECORDED_CROSSWALK_PROVISIONAL
  • Manifest path: docs/external-frameworks/open-policy-agent.json
  • Source reference: https://www.openpolicyagent.org/docs/latest/
  • Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.

Evidence posture

evidence_class: SOURCE_REVIEWED
observed_evidence_class: PARAMETERIZED_OBSERVATION
page_completeness: COMPLETE_WITH_EXTERNAL_GATES
native_runtime_observation: observed
same_environment_replay: observed
fresh_runner_same_provider_replay: observed
StegVerse_bounded_governance_compatibility: observed_6_of_6
independent_implementation_reproduction: false
comparative_testing_claim_allowed: false
bounded_comparative_result_recorded: true
execution_authority_claim_allowed: false

SOURCE_REVIEWED remains the page's non-escalating source boundary required by the public remediation contract. The stronger bounded observation is recorded separately and does not convert the page into a general compatibility, certification, standing, or authority claim.

Published scope

Open Policy Agent is a general-purpose policy engine that evaluates structured input against policy and produces policy decisions.

Canonical source: https://www.openpolicyagent.org/docs/latest/

StegVerse has additionally executed a pinned OPA capture/replay path and a bounded governance-compatibility evaluation. The observed result is limited to the pinned artifacts and six declared case families; it is not a general certification of OPA.

Native terms

OPA termMeaning hereStegVerse relationship
InputStructured facts supplied for evaluation.Evidence input; not standing by itself.
PolicyRego rules and data used to evaluate input.Policy reference that must remain current and scoped.
DecisionOPA evaluation output.Non-authorizing policy evidence; not execution authority.
BundleDeployable policy and data package.Versioned source artifact requiring hash and custody evidence.

Relationship to admissibility

OPA asks: What result follows from this input, policy, and data?
StegVerse asks: May this transition bind consequence at commit time under current identity, authority, policy, delegation, evidence, scope, recoverability, and execution context?

OPA can contribute a policy-decision artifact to a governed transition path. That decision does not establish that the actor has current authority, delegation remains valid, evidence is fresh, or consequence may bind now.

OPA input + policy -> OPA policy decision
OPA decision -> bounded policy evidence
StegVerse -> current state / authority / delegation / evidence / scope evaluation
StegVerse -> ALLOW / DENY / ESCALATE / FAIL_CLOSED
separate commit/execution boundary -> consequence

Evidence Provenance

Canonical evidence:

workflow run: 29455057960
commit: 618a57fb618cd29c90264eb1cab5f4d6814a55f6
validate-chain-continuation: SUCCESS
capture-opa-evidence: SUCCESS
replay-opa-fresh-runner: SUCCESS
OPA governance compatibility evaluator: OBSERVED
cases: 6/6 expected == observed
bounded state: GOVERNANCE_COMPATIBILITY_OBSERVED

The overall workflow concluded failure because a later build-pages job failed; the OPA capture, replay, compatibility execution, and canonical validation jobs completed successfully before that unrelated publication-stage failure.

Preserved artifact evidence:

pinned capture/replay artifact:
id: 8359055203
sha256: 552b50531de1877abc6c5b1546feaa1e45d9aea5800f530da3039b4bb32a580a
fresh-runner replay artifact:
id: 8359059090
sha256: f1d7aaf4a8a1719aba498826cf7b9df4a8f913feb6a6418c8ae23840e268f8ff

Detailed test page: opa-governance-compatibility-test.md.

Expected versus observed outcomes

ConditionExpectedObserved
OPA allow + all StegVerse commit-time conditions currentALLOWMatch
OPA denyDENY / POLICY_DENIALMatch
OPA allow + revoked delegationDENY / AUTHORITY_DRIFTMatch
OPA allow + stale evidenceFAIL_CLOSED / STALE_EVIDENCEMatch
No usable OPA decisionFAIL_CLOSED / FRAMEWORK_RUNTIME_ERRORMatch
OPA allow + target outside current scopeDENY / SCOPE_DIVERGENCEMatch

StegVerse analysis and governance-chain position

CriterionObserved / bounded result
IdentityOPA evaluates supplied attributes; it does not independently establish actor identity.
AuthorityOPA allow does not establish present consequence-binding authority.
PolicyDirect overlap: OPA supplies policy-decision evidence from pinned policy/input.
DelegationMust be reconstructed separately; revoked delegation produced StegVerse DENY even when OPA allowed.
EvidenceOPA output is usable as evidence when input, policy, runtime identity, output, and hashes are retained.
ReplayabilityObserved on same environment and fresh runner using the same OPA implementation/provider.
ReconstructabilityBounded test artifacts and receipts preserve enough state to reconstruct the declared comparison.
Failure behaviorMissing/undefined OPA result remains fail-closed in the StegVerse compatibility evaluator.
InteroperabilityOPA occupies the policy-evaluation evidence layer before StegVerse commit-time admissibility.
Execution authorityNot supplied by OPA and not granted by the compatibility receipt.

Commit-time interoperability contract

Minimum OPA-specific fields:

transition_id
actor
requested_action
target_system
opa_input
opa_decision
opa_query
policy_bundle_reference
policy_bundle_hash
opa_version
data_reference
decision_log_reference
policy_reference
delegation_reference
evidence_references
execution_context
validity_window
source_timestamp

Failure Classes

Failure classObserved or tested boundary
Policy denialOPA allow: false enters as policy evidence and produced DENY / POLICY_DENIAL.
Authority driftOPA allow: true did not override revoked delegation; StegVerse produced DENY / AUTHORITY_DRIFT.
Stale evidenceOPA allow: true did not override stale evidence; StegVerse produced FAIL_CLOSED / STALE_EVIDENCE.
Framework runtime errorMissing usable OPA decision produced FAIL_CLOSED / FRAMEWORK_RUNTIME_ERROR.
Scope divergenceOPA allow: true did not override target mismatch; StegVerse produced DENY / SCOPE_DIVERGENCE.
Replay divergenceSame-environment and fresh-runner decisions matched for the pinned test, but independent implementation/provider reproduction remains unobserved.

Replay path

python scripts/run_pinned_opa_ci_capture.py
python scripts/run_independent_opa_ci_replay.py
python scripts/run_opa_governance_compatibility.py

The fresh-runner replay is stronger than a single local observation but is explicitly not independent-implementation or independent-provider reproduction.

Machine-readable companions

manifest: docs/external-frameworks/open-policy-agent.json
compatibility report: docs/external-frameworks/reports/open-policy-agent.compatibility.json
bounded compatibility status: static/external-frameworks/governance-compatibility-testing-status.v1.json
compatibility receipt (workflow artifact): reports/external-frameworks/opa-independent/opa-stegverse-governance-compatibility-receipt.json
canonical registry: docs/external-frameworks/index.json
canonical union: static/external-frameworks/canonical-union-inventory.v1.json

Remaining external gates

independent organization reproduction: not observed
independent provider reproduction: not observed
independent OPA implementation reproduction: not observed
production StegVerse integration: not established
certification / endorsement: not established
execution authority: not granted

Those gates limit stronger claims; they do not erase the bounded 6/6 observed compatibility result.

Validation Completion Criteria

The local second-page evidence package is complete at the bounded observation level only when all of the following remain inspectable together:

pinned OPA runtime identity
pinned policy and input artifacts
raw capture/replay evidence
same-environment replay receipt
fresh-runner same-provider replay receipt
six predeclared compatibility cases
6/6 expected-versus-observed match
workflow and commit identity
artifact digests
explicit non-equivalence and non-authority boundaries

Independent organization/provider/implementation reproduction is a separate higher evidence class and is not claimed here.

Maintenance and challenge path

Maintenance owner: StegVerse-Labs/admissibility-wiki, External Frameworks audit surface. A challenge should identify open-policy-agent, the disputed field or observed result, and the source or artifact supporting correction. Evidence strength may not be increased without corresponding inspectable evidence.

Non-claims

OPA inclusion is not certification, equivalence, admissibility proof, standing, production integration, or execution authority. A policy allow result does not independently authorize consequence binding. The bounded StegVerse result applies only to the pinned policy/input/replay artifacts and six declared compatibility cases.

This page reflects bounded evidence-governance work. Publication does not create standing.

Next Safe Build Target

Preserve the bounded OPA result while seeking a genuinely independent provider, organization, or alternate implementation reproduction. Until such evidence exists, keep comparative_testing_claim_allowed: false for general claims and preserve the 6/6 result only as a parameterized StegVerse observation.