policy_alert Security Governance

Policy Engine

The policy engine is the decision layer for DAMA. It evaluates request risk, review mode, separation-of-duties, and connector health before a request moves into provisioning.

Auto review Manual review Exception blocks Provisioning handoff
Requests evaluated
Waiting for live queue data.
Auto Review Rate
Waiting for live review rate.
Open Exceptions
Waiting for live exception count.
SoD Blocks
Waiting for live hard block count.

Policy Decision Queue

Requests that were evaluated, routed, or blocked by the engine before provisioning.

Open Queue
Request Object Risk Review Mode Decision Policy Note
Loading live policy decisions...

Policy Evaluation Flow

The engine normalizes the request, evaluates the controls, and sends reviewed requests to provisioning.

5 stages
1 Intake

Capture the request, object type, source connector, requester, and review mode.

2 Evaluate

Check risk, SoD, owner coverage, expiration, and connector health before the request moves forward.

3 Decide

Route the request to auto review, manual review, or a hard block when a policy is violated.

4 Provision

Reviewed requests are handed off to the provisioning queue and executed by the worker service.

5 Reconcile

Store the result, track retries, and write the audit evidence back into the workflow record.

Any request that cannot satisfy the policy rules should stay out of the provisioning queue until it is reviewed or corrected.

Active Rule Set

Policy rules currently shaping review and provisioning decisions.

Live
Birthright access

Low-risk onboarding requests from HR can auto-clear when the manager and department are present.

Auto
Privileged groups

Tier 0, admin, and broad-access groups require manual review and a named owner.

Manual
Separation of duties

Requests that combine requester, decision authority, and fulfillment rights are blocked until an exception is granted.

Block
Connector health

If the downstream worker or connector is degraded, requests stay in review or retry instead of queueing blindly.

Hold
Temporary access

Short-lived elevated access must have an expiry, review date, and a clear rollback path.

Expire

Exceptions & Escalations

Requests that need a human decision, policy override, or retry.

Open Audit
Loading live exceptions...

Decision Mix

How the engine is classifying requests across the current review window.

Loading
Auto-reviewed
Waiting for live policy data.
Manual review
Waiting for live policy data.
Blocked
Waiting for live policy data.
Retry pending
Waiting for live policy data.
IAM/IGA Portal — Internal Use Only. See documentation for policies. Copyright © 2026. All rights reserved.