Immutable, provider-neutral policy lifecycle for agent actions. Drafts are validated and content-digested, versions only increase, activation atomically retires the previous version, evaluations record the exact version and digest, and simulation evaluates an unpersisted candidate without changing live policy.
Provider-neutral evaluation
createAuthzenAdapter() speaks the OpenID AuthZEN evaluation API while custom adapters can target Cedar, OPA, cloud IAM, or an embedded rules engine. PostgreSQL enforces one active version per policy with a partial unique index.
AuthZEN, AARP, and COAZ
Version 0.2 adds direct support for the OpenID AuthZEN AARP and COAZ Working Group Drafts. AARP helpers extract requestable denials, preserve their binding, submit idempotent access requests, persist portable task handles, and only produce approval context for a fresh PDP evaluation. COAZ validates MCP coaz / x-coaz-mapping declarations and constructs single or aligned bulk SARC requests through an injected CEL evaluator. Any mapping, PDP, or decision failure denies tool execution.
Drizzle persistence
Version 0.3 adds @absolutejs/policy/drizzle, a typed Postgres store for production deployments including Neon:
Include policyDrizzleSchema in the host's normal Drizzle migrations; the store never mutates schema at runtime. Activation locks a policy's versions, retires the prior active row, and moves the active pointer transactionally, backed by the one-active partial unique index. PolicyVersionInsertSchema and PolicyVersionSelectSchema are generated from the table with Drizzle-TypeBox. The structural SQL adapter remains available for compatibility, while new Drizzle applications can stay fully typed end to end.
Outcomes
What you can build
Overview
Immutable, provider-neutral policy lifecycle for agent actions. Drafts are validated and content-digested, versions only increase, activation atomically retires the previous version, evaluations record the exact version and digest, and simulation evaluates an unpersisted candidate without changing live policy.
Provider-neutral evaluation
createAuthzenAdapter() speaks the OpenID AuthZEN evaluation API while custom adapters can target Cedar, OPA, cloud IAM, or an embedded rules engine. PostgreSQL enforces one active version per policy with a partial unique index.
AuthZEN, AARP, and COAZ
Version 0.2 adds direct support for the OpenID AuthZEN AARP and COAZ Working Group Drafts. AARP helpers extract requestable denials, preserve their binding, submit idempotent access requests, persist portable task handles, and only produce approval context for a fresh PDP evaluation. COAZ validates MCP coaz / x-coaz-mapping declarations and constructs single or aligned bulk SARC requests through an injected CEL evaluator. Any mapping, PDP, or decision failure denies tool execution.
Hardening checklist
Production guidance
Drizzle persistenceVersion 0.3 adds @absolutejs/policy/drizzle, a typed Postgres store for production deployments including Neon:
Follow in order
Troubleshooting path
1
AuthZEN, AARP, and COAZ
Version 0.2 adds direct support for the OpenID AuthZEN AARP and COAZ Working Group Drafts. AARP helpers extract requestable denials, preserve their binding, submit idempotent access requests, persist portable task handles, and only produce approval context for a fresh PDP evaluation. COAZ validates MCP coaz / x-coaz-mapping declarations and constructs single or aligned bulk SARC requests through an injected CEL evaluator. Any mapping, PDP, or decision failure denies tool execution.