Policy
Discussion
A Policy is a statement of direction, rule, or constraint established by an Authority to guide or control decisions and actions.
A Policy can establish:
-
A required action
-
A permitted action
-
A prohibited action
-
A constraint
-
A decision rule
-
A responsibility
-
A condition
-
A priority
-
An exception
-
An escalation path
-
An enforcement rule
A Policy can apply to:
-
An Organization
-
A User
-
A Role
-
A Node
-
A Node Set
-
An Artifact
-
A Baseline
-
A process
-
A decision
-
An activity
-
Another subject within the Policy’s scope
A Policy can identify:
-
Its identity
-
Its name
-
Its description
-
Its Version
-
Its establishing Authority
-
Its applicable subjects
-
Its applicable scope
-
Its applicable jurisdiction
-
Its applicable conditions
-
Its required actions
-
Its permitted actions
-
Its prohibited actions
-
Its exceptions
-
Its effective time
-
Its expiration time
-
Its status
-
Its precedence
-
Its enforcement mechanism
-
Its superseded Policy
-
Its applicable Evidence
-
Its Provenance
-
Its Traceability
A Policy can be represented as:
-
Natural-language text
-
Structured data
-
A decision table
-
A rule set
-
An executable model
-
A combination of representations
Definition
statement of direction, rule, or constraint established by an Authority to guide or control decisions and actions
Source
Adapted from:
-
DIDO Reference Architecture
-
DIDO Reference Implementation Conceptual Model
-
DIDO-TE draft Requirements Register
This definition establishes Policy as the general concept from which Governance Policy and other specialized Policy types can derive.
Note
A Policy requires an identifiable Authority. A statement without an Authority can express guidance, preference, or convention but does not necessarily establish a Policy.
A Policy differs from a Governance Policy:
-
A Policy provides general direction, rules, or constraints
-
A Governance Policy additionally establishes governance authority, responsibilities, decision rights, and governance processes
Every Governance Policy is a Policy. A Policy is not necessarily a Governance Policy.
A Policy differs from a Requirement:
-
A Policy establishes direction, rules, or constraints
-
A Requirement states a necessary capability, behavior, quality, or constraint that an identified subject must satisfy
A Policy can provide the source or rationale for one or more Requirements. The resulting Requirements must express the applicable obligations in objectively verifiable form.
A Policy differs from a procedure:
-
A Policy establishes what an Authority requires, permits, prohibits, or directs
-
A procedure identifies the activities used to carry out the Policy
A Policy differs from an Acceptance Criterion:
-
A Policy establishes direction, rules, or constraints
-
An Acceptance Criterion establishes a condition used to determine whether an evaluated subject or outcome is acceptable
A Policy can require the establishment or application of Acceptance Criteria.
A Policy differs from a decision:
-
A Policy provides direction or rules for making decisions
-
A decision records a determination made for a particular matter
A Policy does not need to use a particular representation. The same Policy can have human-readable and machine-processable representations.
A machine-processable Policy does not become authoritative merely because a system can execute it. The Authority, approval, scope, effective time, and governing context establish its authority.
Multiple Policies can apply to the same subject. The applicable policy framework must establish how to resolve:
-
Overlapping Policies
-
Conflicting Policies
-
Policy precedence
-
Exceptions
-
Jurisdictional differences
-
Superseded Policies
A Policy is not necessarily:
-
A law
-
A regulation
-
A contract
-
A standard
-
A requirement
-
A procedure
-
An algorithm
-
An executable rule
A law, regulation, contract, or standard can establish or provide the source for a Policy.
A change to a Policy can create a new Version. The applicable change process should preserve:
-
The previous Version
-
The revised Version
-
The reason for the change
-
The approving Authority
-
The effective time
-
The affected subjects
-
The applicable Provenance
-
The applicable Traceability
Example
An Organization establishes a Policy requiring every Test Run used for a Validation Decision to preserve:
-
The applicable Test Object Versions
-
The applicable Test Environment
-
The applicable Test Argument Values
-
The applicable Executable Artifact Versions and content digests
-
The applicable Execution Facility Versions and configurations
-
The resulting Test Results
-
The assigned Verdicts
-
The supporting Evidence
-
The applicable Provenance
-
The applicable Traceability
The Policy provides the source for specific DIDO-TE Requirements governing Test Run records and Evidence preservation.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.