A policy applies to the calls it receives

Policies match typed calls, a deny wins, and every decision names its policy revision.

Match a defined input

Policy evaluation works on the input supplied to it. Commands that bypass an installed integration cannot be stopped by that integration.

Keep the version

Security records bind decisions to policy revisions so a changed rule does not silently replace the rule that made an earlier decision.

Bind exceptions to their action

Exception checks use the action and authority they were issued for. An approval is not blanket permission for the rest of a session.

Separate evaluation from rollout

Policy evaluation, publication, adapter installation and device enrollment are separate steps. A policy file or successful simulation does not establish that a client is enforcing it.