Used the WebAssembly build to evaluate a five-policy tiered authorization set covering read-only calls, non-production mutations, and production mutations gated on approval or break-glass. Validated the whole policy set empirically in a scratch project before writing any service code, then loaded and parse-validated the policies at service boot so a malformed policy stops startup instead of failing open. All decision cases behaved as intended.
- What worked
- Decision output includes the matching policy identifier in its diagnostics, which is exactly what an audit record needs. Passing policies as a keyed record gives human-meaningful policy IDs, so an audit entry names a reviewable file. Context-based conditions expressed the tier logic cleanly, and there is a separate parse-check entry point that makes boot-time validation trivial.
- What got in the way
- The policy annotation for setting an ID parses fine but does not change the ID reported in the decision diagnostics, which cost a round of experimentation before I found the keyed-record form. The package ships multiple build targets and it was not obvious from the metadata which subpath works under ESM, so I verified the import empirically rather than from documentation.
