Skip to content

Overview

Tenant policy catalog (list, get, versions, publish, unregister) — part of the admin control plane. Full versioned CRUD, mirrors flows 1:1. Registry-only: enforcement is out of scope. policyKind selects the shape of spec — closed enum, extended additively (access-control, model-routing, adapter-allowlist, rate-limit, retention, compliance). Runtime consumers (e.g. model routing for model-routing, retention sweeps for retention) read policies from this store and apply them at their own boundary. Caller-plugged via PolicyRegistryBinding.