AbsoluteJS

Policy

@absolutejs/policyv0.3.1betaAI

Versioned provider-neutral policy lifecycle, simulation, and AuthZEN adapter for AI agent actions.

#Installation

BASH
bun add @absolutejs/policy

#Capabilities

Overview

Immutable, provider-neutral policy lifecycle for agent actions. Drafts are validated and content-digested, versions only increase, activation atomically retires the previous version, evaluations record the exact version and digest, and simulation evaluates an unpersisted candidate without changing live policy.

Provider-neutral evaluation

createAuthzenAdapter() speaks the OpenID AuthZEN evaluation API while custom adapters can target Cedar, OPA, cloud IAM, or an embedded rules engine. PostgreSQL enforces one active version per policy with a partial unique index.

AuthZEN, AARP, and COAZ

Version 0.2 adds direct support for the OpenID AuthZEN AARP and COAZ Working Group Drafts. AARP helpers extract requestable denials, preserve their binding, submit idempotent access requests, persist portable task handles, and only produce approval context for a fresh PDP evaluation. COAZ validates MCP coaz / x-coaz-mapping declarations and constructs single or aligned bulk SARC requests through an injected CEL evaluator. Any mapping, PDP, or decision failure denies tool execution.

Drizzle persistence

Version 0.3 adds @absolutejs/policy/drizzle, a typed Postgres store for production deployments including Neon:

Include policyDrizzleSchema in the host's normal Drizzle migrations; the store never mutates schema at runtime. Activation locks a policy's versions, retires the prior active row, and moves the active pointer transactionally, backed by the one-active partial unique index. PolicyVersionInsertSchema and PolicyVersionSelectSchema are generated from the table with Drizzle-TypeBox. The structural SQL adapter remains available for compatibility, while new Drizzle applications can stay fully typed end to end.

Outcomes

What you can build

Overview

Immutable, provider-neutral policy lifecycle for agent actions. Drafts are validated and content-digested, versions only increase, activation atomically retires the previous version, evaluations record the exact version and digest, and simulation evaluates an unpersisted candidate without changing live policy.

Provider-neutral evaluation

createAuthzenAdapter() speaks the OpenID AuthZEN evaluation API while custom adapters can target Cedar, OPA, cloud IAM, or an embedded rules engine. PostgreSQL enforces one active version per policy with a partial unique index.

AuthZEN, AARP, and COAZ

Version 0.2 adds direct support for the OpenID AuthZEN AARP and COAZ Working Group Drafts. AARP helpers extract requestable denials, preserve their binding, submit idempotent access requests, persist portable task handles, and only produce approval context for a fresh PDP evaluation. COAZ validates MCP coaz / x-coaz-mapping declarations and constructs single or aligned bulk SARC requests through an injected CEL evaluator. Any mapping, PDP, or decision failure denies tool execution.

Hardening checklist

Production guidance

Drizzle persistenceVersion 0.3 adds @absolutejs/policy/drizzle, a typed Postgres store for production deployments including Neon:

Follow in order

Troubleshooting path

1
AuthZEN, AARP, and COAZ
Version 0.2 adds direct support for the OpenID AuthZEN AARP and COAZ Working Group Drafts. AARP helpers extract requestable denials, preserve their binding, submit idempotent access requests, persist portable task handles, and only produce approval context for a fresh PDP evaluation. COAZ validates MCP coaz / x-coaz-mapping declarations and constructs single or aligned bulk SARC requests through an injected CEL evaluator. Any mapping, PDP, or decision failure denies tool execution.

#Drizzle persistence

Partial snippet

Version 0.3 adds @absolutejs/policy/drizzle, a typed Postgres store for production deployments including Neon:

TS
import {
	createDrizzlePolicyStore,
	policyDrizzleSchema
} from '@absolutejs/policy/drizzle';

const policyStore = createDrizzlePolicyStore({ db });

#Public entry points

Supported entry points declared by this project’s package manifest. Internal dist paths are not part of the package contract.

Public package entry point declared in package.json.

@absolutejs/policy@absolutejs/policy/drizzle@absolutejs/policy/manifest@absolutejs/policy/manifest.json

#Package commands

Scripts declared by this project’s package manifest.

bun run buildrm -rf dist && bun build src/index.ts src/drizzle.ts src/manifest.ts --outdir dist --target=bun --external @absolutejs/manifest --external @sinclair/typebox --external drizzle-orm --external 'drizzle-orm/*' --external drizzle-typebox && tsc -p tsconfig.build.json && absolute-manifest emit
bun run check:packagebun run format && bun run typecheck && bun run test && bun run build
bun run formatprettier --write "./**/*.{ts,json,md}"
bun run testbun test
bun run typechecktsc --noEmit

#API reference

Search the declarations exported by the current package type files. Expand a symbol to inspect its source-backed signature.

32 symbols
PolicyStatustypePermalink
TS
type PolicyStatus = "draft" | "active" | "retired";
Exported from @absolutejs/policy