# Author Policies with the SDK

> Define deterministic executable Policy decisions and use canonical identity, action, Resource, and constraint contracts.

Use `policy()` for every public Policy package. It accepts executable Policy definitions only; declarative statements are not a public authoring or Resource-creation API. Policy code returns one outcome value. The execution environment owns request and outcome hashes.

## Executable Policy {#executable-policy}

```ts
import { policy } from "@constal/sdk";

export default policy({
  id: "ticket-read", version: "1.0.0",
  evaluate(input) {
    const allowed = input.action === "resource:invoke"
      && input.context["resource.operation"] === "ticket.read";
    return allowed
      ? { kind: "allow" as const }
      : { kind: "deny" as const, code: "operation-denied", reason: "operation denied" };
  },
});
```

The evaluator has no network, secret, storage, clock, random, timer, or trusted-runtime capability. It receives normalized identity, exact action and Resource, bounded context, optional invocation data, and a requested grant when applicable. Return exactly one `allow`, `deny`, `require-approval`, `substitute`, `constrain`, or `grant` outcome. Explicit deny wins; scopes only narrow existing authority. Unsupported outcomes or constraints deny at the consuming boundary.

Package the definition with `constal.policy.json`. Its required `target` names exactly one `resourceKind` and a normalized label selector. The selector determines attachment; Policy code does not declare Resource patterns and invocation arguments cannot change membership.

Built-in governance helpers such as `sandboxControls()`, `sandboxLimit()`, `modelControls()`, `modelLimit()`, and `agentLimit()` create typed constraints for an exact Resource governance contract. The platform validates them against the target contract, derives customer/subject/tenant scope from trusted authority, reserves hard limits before dispatch, and passes only effective controls to the provider. Continue with [Govern Resource usage](/docs/policies/governance.md), [Author a Policy](/docs/policies/author.md), and [CLI Policy evaluation](/docs/policies/cli.md).
