Policy System Overview

Audience: Policy authors, reviewers, and operators getting their bearings before diving into the language, lifecycle, or runtime guides. Scope: What the Policy system does, its layers and inputs, and how policies are governed and enforced online and in air-gapped sites.

Imposed rule: Policies that change reachability or trust weighting must enter shadow mode first and ship coverage fixtures; promotion is blocked until shadow + coverage gates pass (see the Policy Lifecycle & Approvals guide).

This overview orients authors, reviewers, and operators to the Stella Ops Policy system: the SPL language, lifecycle, evidence inputs, and how policies are enforced online and in air-gapped sites.

1. What the Policy System Does

2. Layers

3. Inputs & Signals

4. Lifecycle (summary)

  1. Draft in SPL with shadow mode on and coverage fixtures (stella policy test).
  2. Submit with lint/simulate + coverage artefacts attached.
  3. Review/approve with Authority scopes; determinism and shadow gates enforced in CI.
  4. Publish/attest (DSSE + optional Rekor); promote to environments; activate runs.
  5. Archive or roll back with audit trail preserved.

5. Governance & Roles

6. Review Checklist (fast path)

7. Air-gap / Offline Notes

8. Key References