Skip to content
Draft - v1alpha1. Fields and semantics may change before v1beta1.

Policy-as-Code

apiVersion: awp.agenticworkflowprotocol.org/v1alpha1
kind: Policy
metadata:
name: no-production-autonomy
version: 1.0.0
owner:
team: platform-governance
spec:
rules:
- id: deploy-needs-release-manager
when:
action: production.deploy
effect: requireApproval
approval:
approvers:
- role: release-manager
  • A rule has a when condition and an effect (allow, deny, requireApproval).
  • Every evaluation produces a policy.evaluated event; denials produce policy.denied.
  • Decisions of several sources are combined by a defined algorithm; an unevaluable policy denies.
  • Policies are reusable Policy manifests that workflows reference.

Normative text: Kind Policy and policy evaluation, Decision combination.