{"schemaVersion":"0.1","generatedAt":"2026-10-09T19:43:43.895Z","entry":{"knowledgeKey":"policy-application","kind":"capability","entityKey":"policy-lifecycle","locale":"en","primaryQuestion":"What is a policy in MeshQu, and how is it applied to a decision?","questionVariants":[{"question":"What does MeshQu mean by a policy?"},{"question":"How does a policy decide the verdict on a decision?"},{"question":"Who approves a policy change before it takes effect?"},{"question":"Can a new policy be tried without affecting live decisions?"}],"title":"What a policy is, and how it is applied","answer":"A policy is a named, versioned configuration applied to a decision context. The rules come from the approved policy, and a recorded assessment is tied to the policy version that governed it. Ordinary evaluation uses the active version; a frozen form can use its eligible, ratified pinned version. The verdict is advisory: your systems control the action. Human ratification governs policy changes; maker-checker separation depends on the tenant setting.","explanation":"Use the approved policy to identify the rules a decision is checked against; the recorded assessment is tied to the governing policy version, which is not a claim that the receipt records the outcome for each individual rule. Ordinary evaluation resolves the active version. A frozen form instead evaluates against the exact policy version pinned on it, which must be eligible and ratified; a superseded but ratified version can therefore continue to govern that form while a newer version is active. Reading a draft or historical version never changes evaluation. Ratifying a policy change makes it active. Tenants can enable maker-checker enforcement so that the ratifier cannot be the draft author; when it is disabled, self-ratification is possible. Shadow mode turns a deny verdict into an alert for observation. Your application continues to own enforcement in every case.","applications":[{"value":"Establish which policy version a recorded decision was evaluated against, and compare it with the version in force now."},{"value":"Separate authorship from policy ratification where maker-checker is enabled, rather than assuming that every deployment requires a second person."},{"value":"Observe how a proposed policy would behave on real decision traffic before switching it to enforcement."}],"limitations":[{"value":"MeshQu does not block, allow or modify an operation. It returns a verdict, and the calling application acts on it."},{"value":"Submit and reject are documented as available in a future release; the action matrix emits approve (ratify), discard, compare and restore today."},{"value":"Maker-checker is a tenant setting. When it is disabled, the draft's author can ratify their own draft, so a separate approver is not guaranteed by the product alone."},{"value":"Whether maker-checker or shadow mode is enabled in any particular deployment is not publicly confirmed. Confirm it for yours."},{"value":"This entry describes the documented behaviour of the policy API. It is not a statement that any customer deployment is running it."},{"value":"A receipt is tied to the governing policy version. A rule-by-rule assessment view does not establish the outcome for each individual rule or the evidence for each rule in the receipt."}],"nextStep":{"label":"How policy versions are governed","href":"https://docs.meshqu.com/concepts/policy-lifecycle"},"claims":[{"claimKey":"policy-is-versioned-configuration","statement":"A policy is a named, versioned governance configuration applied to a decision context. Ordinary evaluation uses the active version, but a frozen form evaluates against its eligible, ratified pinned version, which can be superseded.","qualification":"Reading a version does not change evaluation. A draft cannot be an eligible frozen pin; the documentation states the ratification requirement."},{"claimKey":"four-verdicts-advisory","statement":"Evaluating a decision context against the applicable policies returns one of four verdicts — allow, review, deny or alert. The verdict is advisory: the calling application decides what to do with it.","qualification":"Alert is the advisory-mode outcome: a policy that would deny, logged for observation."},{"claimKey":"approval-makes-a-version-active","statement":"A policy change takes effect through approval: ratifying a submitted draft makes it the new active version and turns the previous active version historical. Tenants can enable maker-checker enforcement to require that a different person approves a draft than the one who created it, and the check is enforced server-side on the ratify endpoint.","qualification":"When maker-checker is disabled, the author can ratify their own draft. Submit and reject transitions are documented as available in a future release."},{"claimKey":"shadow-mode-downgrades-deny","statement":"A policy carries a shadow-mode flag that downgrades deny verdicts to alert when enabled, so a new policy can be observed without production impact before it is switched to enforcement.","qualification":"Whether shadow mode is enabled in a given environment is not publicly confirmed."},{"claimKey":"policy-changes-receipted","statement":"Policy changes are themselves governed and receipted.","qualification":"Recorded as 'TRUE TODAY' in the 17 July 2026 verified-claims register, taken from the internal audit's claims table. Not independently re-verified since that date."}],"statementKind":"capability","availability":"limited-pilot","evidenceStrength":"source-reported","publicSources":[{"title":"MeshQu docs — Concepts overview","url":"https://docs.meshqu.com/concepts/overview","context":"The documentation owner's definition of a policy and of the four decision outcomes, including that the decision is advisory."},{"title":"MeshQu docs — Policy lifecycle","url":"https://docs.meshqu.com/concepts/policy-lifecycle","context":"The governing-version exception for frozen forms, version states and the optional maker-checker requirement."},{"title":"MeshQu docs — Integration patterns","url":"https://docs.meshqu.com/guides/integration-patterns","context":"Who enforces the verdict, and the advisory-rollout pattern that uses shadow mode."}],"canonical":{"externalUrl":"https://docs.meshqu.com/concepts/policy-lifecycle"},"revision":"60fe21b0a61ee00e4f172ac59a126325dcee8220baf55bb1a7c8fc53e57030ee","updatedAt":"2026-10-09T11:41:00.666Z","canonicalUrl":"https://docs.meshqu.com/concepts/policy-lifecycle","related":[{"key":"what-meshqu-does","url":"https://www.meshqu.com/knowledge/what-meshqu-does.json"},{"key":"decision-receipts","url":"https://www.meshqu.com/knowledge/decision-receipts.json"}]}}