Policy Governance

Audience: Policy approvers, security leads, compliance owners, and operators responsible for sign-off and audit. Scope: Roles and Authority scopes, the approval workflow, signing/attestation, exception handling, and the audit trail for Stella Ops policies.

Imposed rule: Publish and promote actions require reason + ticket metadata and a DSSE attestation; two-person approval is recommended and enforced where configured by Authority.

This guide defines the roles, scopes, approvals, signing, and exception handling that govern Stella Ops policies. Pair it with the Policy System Overview for the big picture and the Policy Lifecycle & Approvals guide for the stage-by-stage workflow.

1. Roles & scopes

Authority can map organisational roles to scopes; the two-person rule can be enabled per tenant for publish/promote.

2. Approval workflow

  1. Author drafts with shadow + coverage fixtures, then runs lint/simulate/test.
  2. Submit with attachments (lint, simulate, coverage; reason/ticket optional at this stage).
  3. Reviewers comment and resolve; the approver checks gates (shadow, coverage, determinism).
  4. Publisher runs stella policy publish --reason --ticket --sign; the attestation is stored and optionally mirrored to Rekor.
  5. Operator activates the version; audit events are recorded.

3. Signing & attestation

4. Exceptions & waivers

5. Compliance checklist

6. Audit & observability

References