Capture the request, object type, source connector, requester, and review mode.
Policy Engine
The policy engine is the decision layer for DAMA. It evaluates request risk, review mode, separation-of-duties, and connector health before a request moves into provisioning.
Policy Decision Queue
Requests that were evaluated, routed, or blocked by the engine before provisioning.
| Request | Object | Risk | Review Mode | Decision | Policy Note |
|---|---|---|---|---|---|
Loading live policy decisions... |
|||||
Policy Evaluation Flow
The engine normalizes the request, evaluates the controls, and sends reviewed requests to provisioning.
Check risk, SoD, owner coverage, expiration, and connector health before the request moves forward.
Route the request to auto review, manual review, or a hard block when a policy is violated.
Reviewed requests are handed off to the provisioning queue and executed by the worker service.
Store the result, track retries, and write the audit evidence back into the workflow record.
Active Rule Set
Policy rules currently shaping review and provisioning decisions.
Low-risk onboarding requests from HR can auto-clear when the manager and department are present.
Tier 0, admin, and broad-access groups require manual review and a named owner.
Requests that combine requester, decision authority, and fulfillment rights are blocked until an exception is granted.
If the downstream worker or connector is degraded, requests stay in review or retry instead of queueing blindly.
Short-lived elevated access must have an expiry, review date, and a clear rollback path.
Exceptions & Escalations
Requests that need a human decision, policy override, or retry.
Decision Mix
How the engine is classifying requests across the current review window.