Skip to main content

Open Policy Agent

Generated Evaluation Status

This section is generated from the framework manifest and compatibility report. Do not edit it manually.

  • Framework ID: open-policy-agent
  • Manifest: docs/external-frameworks/open-policy-agent.json
  • Compatibility report: ./reports/open-policy-agent.compatibility.json
  • Evidence class: SOURCE_REVIEWED
  • Independently reproducible: False
  • Comparative-testing claim allowed: False
  • Missing reproducibility gates: shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction
  • Evaluation result: COMPATIBILITY_EVIDENCE_ONLY
  • Cycle status: FIRST_FRAMEWORK_CYCLE_COMPLETE
  • Execution authority claim: False
  • Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
  • Posting source: generated compatibility report
  • Generated status is descriptive compatibility evidence only.

Generated Authored Analysis Boundary

This section is generated. Do not edit it manually.

  • Framework ID: open-policy-agent
  • Framework name: Open Policy Agent
  • Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
  • Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
  • Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
  • Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.

Generated Transition Mapping

This section is generated from the framework manifest. Do not edit it manually.

FieldGenerated Value
framework_identityOpen Policy Agent
source_referencehttps://www.openpolicyagent.org/docs/latest/
source_versionofficial documentation recorded
allowed_use_boundarypolicy-decision evidence only
claimsstructured policy evaluation
non_claimsno admissibility proof or execution authority
input_artifact_typestructured input and policy
output_artifact_typepolicy decision artifact
actor_or_authority_modelexternal policy engine; authority not inherited
evidence_modelofficial source plus bounded crosswalk
policy_or_rule_modelpolicy rules
delegation_modelnot established by OPA
decision_or_result_modelpolicy decision evidence
execution_authority_claimfalse
receipt_or_trace_modelmanifest and report references
reconstruction_modelsource and mapping reconstruct the bounded relationship
SPE_overlappolicy evidence may inform standing review
StegVerse_ecosystem_overlapcommitment-boundary policy evidence
fail_closed_conditionsmissing source, mapping, or authority overclaim

Generated mapping is compatibility evidence only.

Generated Framework Metadata

This section is generated from the external-framework registry. Do not edit it manually.

  • Framework ID: open-policy-agent
  • Name: Open Policy Agent
  • Registry status: SOURCED-CROSSWALK-PROVISIONAL
  • Testbench state: SOURCE_RECORDED_CROSSWALK_PROVISIONAL
  • Manifest path: docs/external-frameworks/open-policy-agent.json
  • Source reference: https://www.openpolicyagent.org/docs/latest/
  • Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.

Evidence posture

evidence_class: SOURCE_REVIEWED
page_completeness: COMPLETE_WITH_EXTERNAL_GATES
runtime_observation: none attached
independent_reproduction: false
comparative_testing_claim_allowed: false
execution_authority_claim_allowed: false

Published scope

Open Policy Agent is a general-purpose policy engine that evaluates structured input against policy and produces policy decisions.

Canonical source: https://www.openpolicyagent.org/docs/latest/

Source snapshot posture: official documentation is recorded, but no pinned OPA release, policy bundle hash, runtime configuration, raw decision log, or independent replay receipt is attached to this page.

Native terms

OPA termMeaning hereStegVerse relationship
InputStructured facts supplied for evaluation.Evidence input; not standing by itself.
PolicyRego rules and data used to evaluate input.Policy reference that must remain current and scoped.
DecisionOPA evaluation output.Commitment Candidate evidence; not execution authority.
BundleDeployable policy and data package.Versioned source artifact requiring hash and custody evidence.

Relationship to admissibility

OPA asks: What result follows from this input, policy, and data?
StegVerse asks: May this transition bind consequence at commit time under current identity, authority, policy, delegation, and evidence?

OPA can contribute a policy-decision artifact to a governed transition path. That decision is evidence about policy evaluation; it does not establish that the actor has current authority, that delegation remains valid, or that consequence may bind now.

OPA input + policy -> policy decision
policy decision -> Commitment Candidate evidence
SPE -> reconstruct current standing
SPE result -> ALLOW / DENY / FAIL-CLOSED

Observation boundary

No public StegVerse runtime observation is claimed on this page.

shared test vector: missing
raw output: missing
timestamp: missing
runtime configuration: missing
source version or hash: missing
replay commands: missing
declared expected outcome: missing
independent reproduction: missing

The compatibility report must remain SOURCE_REVIEWED until these fields are public and inspectable.

StegVerse analysis

CriterionCurrent result
IdentityOPA evaluates supplied attributes; it does not independently establish actor identity.
AuthorityAn allow decision does not establish current consequence-binding authority.
PolicyStrong overlap: OPA can produce inspectable policy decisions when policy identity is pinned.
DelegationDelegation must be supplied and reconstructed separately.
EvidenceDecision logs can become evidence when inputs, policy bundle, version, and output are retained.
ReplayabilityPossible only with pinned engine, bundle, data, input, and configuration.
ReconstructabilityPartial until complete input and decision provenance are retained.
Failure behaviorIntegration must fail closed on missing policy, undefined result, stale bundle, or evaluation error.
InteroperabilityOPA output can route into a Commitment Candidate as non-authorizing policy evidence.

Commit-time interoperability contract

Minimum OPA-specific fields:

transition_id
actor
requested_action
target_system
opa_input
opa_decision
opa_query
policy_bundle_reference
policy_bundle_hash
opa_version
data_reference
decision_log_reference
policy_reference
delegation_reference
evidence_references
execution_context
validity_window
source_timestamp

Failure classes

Failure classAppliesCurrent evidence posture
Semantic equivalence divergenceYesOPA allow/deny must not be equated with StegVerse ALLOW/DENY.
Authority driftYesAuthority can change after policy evaluation.
Stale evidenceYesPolicy bundles and input facts can become stale.
Delegation leakageYesSupplied roles or claims may exceed current delegation.
Replay divergenceYesDifferent engine, bundle, data, or configuration can change output.
Fail-open runtime errorYesUndefined or errored evaluations must not authorize execution.
Source-claim mismatchYesDocumentation or policy labels may not match the deployed artifact.

Machine-readable companions

manifest: docs/external-frameworks/open-policy-agent.json
compatibility report: docs/external-frameworks/reports/open-policy-agent.compatibility.json
canonical registry: docs/external-frameworks/index.json
canonical union: static/external-frameworks/canonical-union-inventory.v1.json

Maintenance and challenge path

Maintenance owner: StegVerse-Labs/admissibility-wiki, External Frameworks audit surface.

A challenge must identify the framework ID open-policy-agent, the disputed field or claim, the source or artifact supporting the correction, and whether the requested change affects source posture, evidence class, page completeness, or standing. No challenge may increase evidence strength without corresponding public artifacts.

Validation completion criteria

pinned OPA release or binary identity
pinned policy bundle and data hashes
shared input vectors
predeclared expected boundaries
raw decision outputs and errors
timestamps and runtime configuration
replay commands
independent rerun receipt
non-claim language preserved

Benchmark relevance

commitment_boundary, authority_boundary, unknown_trajectory_boundary, interoperability_path

Non-claims

OPA inclusion is not certification, equivalence, admissibility proof, or StegVerse standing. A policy allow result does not independently authorize consequence binding. This page does not claim live integration, production deployment, or general compatibility.

Next safe build target

Attach one pinned OPA decision bundle with input, Rego and data hashes, raw output, runtime configuration, expected StegVerse boundary, replay command, and an independent rerun receipt.

This page reflects a bounded admissibility packet. Publication does not create standing. The reflected claim inherits only the standing reconstructable from the referenced evidence, authority, and admissibility conditions.