Our State of Authorization: AI Edition is now available Get it now »

Policy management 101: Everything you need to know about policies

Policy Management can seem daunting at first, but by breaking it down into clear steps, organizations can create a clear policy framework.

Policy management plays a crucial role in maintaining security and efficiency within an organization.

However, navigating the complexities of who writes policies, how much time is needed for maintenance, and the best methods for testing can be challenging. By breaking these topics down into actionable steps, organizations can establish a clear framework for creating, maintaining, and testing policies that align with their unique needs.

Who writes the policies?

The answer to this question really depends on the organization. There is no established rule that says the developer has to be the one to write the policies. In some organizations, the answer isn’t even a human user, but rather, artificial intelligence (AI). All in all, it really could be anybody writing these policies, but popular choices include developers and application owners.

Our solution doesn’t force you into a singular approach — it supports flexibility. The real question you should be asking is:

How close are you to the thing you want to protect?

For instance, if you’re protecting an application, the individuals most likely to write the policies are those closest to it such as the product owner, the application owner, or the application developer. Compliance teams who care about the internal legislation of the application may also get involved. In some cases,  the legal or external compliance teams might contribute as well, particularly when regulations like GDPR and other government mandates are involved. The IT and security teams may play a role too, depending on the organization’s structure.

Ultimately, you could have two separate teams at a high level that write policies:

  • Local teams: Such as the application owner or developer of the application, who understand the specific needs of an individual application.
  • Global or cross-enterprise teams: Like compliance, security, or governance teams, who create policies that apply organization-wide.

With externalized authorization, these teams can work together. A global policy can provide a consistent foundation across all applications, while a local policy can address specific requirements of a particular application.

There’s also instances where enterprises will have a security team who creates a library of global standard policies, policy trees, or even rules. These resources are then shared with individual business groups to use as a guideline when writing their own policies.

How much time will I spend maintaining my policies?

Though it may seem too good to be true, the answer is: Not much time at all!

Maintaining policies is a lot different than creating new ones. While creating new policies completely from scratch seems like a bit of a snowball effect, maintaining already existing policies is a lot more straightforward. This is because of a couple different reasons.

Firstly, you’re already familiar with the existing policies. That familiarity gives you confidence, which takes the guesswork and brainstorming out of the equation. You know the structure and intent of the policy, so you’re able to work more efficiently.

Secondly, most of these policies are built around compliance either from the government or your organization’s own internal authorization requirements. That means they already have a solid backbone, and they don’t tend to change very often.

These types of rules don’t focus on the user’s attribute values, but rather, they evaluate  relationships — for example, “Are you the owner of this document?”. In other words, this environment is similar to the traffic laws in your area. The drivers and cars may change constantly (just like user attributes), but the traffic rules such as stop signs, speed limits, traffic lights, etc., remain the same. It’s the consistency that makes the process faster.

How do I test my policies?

There are many different ways to test policies, but there are two common ways:

  1. Traditional Unit Testing via PEP/PDP/API: This approach focuses on targeted, specific questions — essentially unit tests. You might ask, “Can Alice view record 1?” and then compare the system’s response to what you were expecting to know whether that is the right response.
  2. Partial Evaluation with Contextual Authorization Query (CAQ):This method allows for broader questions like “what can interns look at?” or “who can view company secrets?” By using CAQ, this approach helps uncover the full scope of what your policies allow, which is useful in auditing and compliance scenarios.

The Policy Testing Framework

In addition to common practices, there’s also the Policy Testing Framework (Axiomatics DevOps) which helps you define tests and run them. It allows you to to write a set of tests in which you provide attributes as well as your expected responses and what obligations and advice you’re looking for. For example, given these attributes I can expect this result and it gives you a pass/fail. This tool allows you to do this testing with attribute connectors, policy information points, or even without so that you as the user can take complete control of the values of these attributes.

It also provides tracing meaning that this test will help you not only see that it failed, but why it failed. Visually, this tool provides you with a visual representation of where it went and where the decision came from to better help you understand why you got a deny when you expected a permit in real time.

This sort of testing is really beneficial when you’ve come across role explosion and want to check on existing policies. As your policies evolve, compliance standards change, and security polices grow, you’re able to make sure that even if this is the 30th or 40th policy, they’re all still giving you the behavior that you want.

Ultimately, this visual representation is helpful in keeping your policies in-tact and up-to-date, giving you quick reasonings as to why certain outcomes are happening.

How do I achieve success in policy authoring?

Embarking on a policy authoring journey can feel like stepping into a maze. The bigger picture — defining rules, balancing perspectives, meeting compliance standards — can easily overwhelm even the most seasoned professionals. However, crafting effective policies doesn’t have to be an uphill battle. By breaking the process into clear, manageable steps, you can stay focused, avoid unnecessary complexity, and ensure that your policies meet organizational goals.

Some of the steps include:

  • Engage the right stakeholders and define requirements;
  • Think in terms of plain, old English;
  • Think about the default use case;
  • And more.

Want to take a deeper dive into policy authoring? Check out our article where we break down ten rules to successful policy authoring..

Building stronger policies for organizational resilience

Managing policies doesn’t have to be an overwhelming endeavor. With the right tools and strategies, you can simplify policy creation, reduce maintenance efforts, and ensure accuracy through effective testing. A well-managed policy system ultimately ensures reliable operations, strengthens defenses, and lays the groundwork for sustained success.

Want to see authorization in action? Request a demo with our solution experts to see how we can:

Have 30 minutes? Let's show you a demo!

See how our award-winning solution can help you meet today's access control and Zero Trust needs.

Request a demo

  Join us on LinkedIn for more insights
Archived under:
About Axiomatics

The world’s largest enterprises and government agencies continually depend on Axiomatics’ award-winning authorization platform to share sensitive, valuable and regulated digital assets – but only to authorized users and in the right context.