# Operate Policies with the CLI

> Deploy, inspect, and evaluate immutable Policies before attaching them to operational boundaries.

## Before you begin {#before-you-begin}

Prepare an executable Policy package or existing Policy CRN, representative allowed and denied inputs, and `policy:evaluate` authority. Keep principal and customer context faithful to production. Put the Resource kind and selector in `constal.policy.json`; use protected `constal.ai/crn` rather than a display name when selecting one exact Resource.

## Steps {#steps}

1. Deploy an executable Policy package through `constal deployments create policy.zip` and poll publication.
2. Put the normalized test input in a reviewed file containing `action`, `resource`, and optional bounded `context`.
3. Evaluate it through the public Policy endpoint:

   ```sh
   constal policies evaluate ticket-boundary --body @policy-input.json --output json
   ```

4. Repeat with a negative case and confirm explicit denial and expected constraints.
5. Inspect the exact Resource set selected by the deployed manifest. Change and redeploy the Policy package when the selector changes; do not create a separate Resource-pattern or attach-everywhere path.
6. Start a controlled Run and compare its pinned Policy hash with the currently deployed Policy.

The CLI does not provide an “attach everywhere” shortcut. An empty label selector intentionally selects every Resource of the declared kind inside the trusted environment, tenant, and namespace boundary.

## Verify {#verify}

Confirm denied operations stop before external dispatch. Verify an existing Run retains its accepted Policy snapshot unless an authenticated safe-point Policy control changes it. Record the deployment and evaluation output for review.

## Next steps {#next-steps}

Use [Author Policies with the SDK](/docs/policies/sdk.md), [Operate Policies](/docs/policies/operate.md), and the generated [Policies command reference](/docs/cli/reference.md#policies).
