Match a defined input
Policy evaluation works on the input supplied to it. Commands that bypass an installed integration cannot be stopped by that integration.
Keep the version
Security records bind decisions to policy revisions so a changed rule does not silently replace the rule that made an earlier decision.
Bind exceptions to their action
Exception checks use the action and authority they were issued for. An approval is not blanket permission for the rest of a session.
Separate evaluation from rollout
Policy evaluation, publication, adapter installation and device enrollment are separate steps. A policy file or successful simulation does not establish that a client is enforcing it.
Check availability before relying on it
User-facing simulation, exports and client coverage need their own release checks. This note is not a promise of those services for a newly created account.