thalos-domain/docs/migration/policy-behavior-invariants.md
2026-02-25 13:13:56 -06:00

14 lines
589 B
Markdown

# Policy Behavior Invariants
## Invariants
- Equivalent policy inputs produce equivalent policy decisions.
- Token decision fallback behavior remains stable until explicitly revised.
- Provider semantics are explicit:
- `InternalJwt`: standard identity permission evaluation.
- `AzureAd` and `Google`: policy permission must remain within `identity.*` scope.
- Service transport contracts remain stable during domain extraction.
## Validation Approach
- Capture pre/post decision examples for policy and token flows.
- Validate delegation path: service orchestrates, domain decides.