The Life of a Rule
A rule is software: it needs a test suite, an owner, a version consumers pin, and a decision record when it blocks the wrong change. Interviewers probe it because policy programmes die of neglect.
on this pageshowhide
explore
- Writing a Testable Rule12 questions
- Owning and Shipping Rules16 questions
- Rule Ownership & Review4 questions
- Reaching Every Enforcer4 questions
- Rule Bundle Integrity4 questions
- Rule Identity & Reuse4 questions
- Rules in Production16 questions
- Diagnosing a Denial4 questions
- Decision Latency Budget4 questions
- Effectiveness & Retirement4 questions
- Upgrades That Break Rules4 questions
questions
page 2 of 2Before a policy engine major upgrade, how do you prove your rules still deny what they denied before?
basics
~20 sReplay a corpus of the estate's real stored objects through both the old and the new engine-and-rules pair, then diff the decisions. Deny-to-allow flips are enforcement regressions; allow-to-deny flips are the blast radius you are about to inflict.
A rule defaults audit-log retention to 30 days; another denies anything under 90. How do you fix this?
basics
~20 sTwo rules own the same field with different intents: validation judges the value the defaulting rule just wrote. Give the field one authority - make the default compliant - and test the two rules together rather than separately.
How do you retire a policy rule that other teams' pipelines import, without breaking them?
basics
~20 sTreat the rule as a published interface with consumers. Decide whether the control is going or only this encoding, enumerate who imports it, announce a dated removal sized to the slowest consumer, then actually delete it - never leave an always-allow stub.
Your audit-log retention rule duplicates a control your nightly benchmark run already checks - which one survives?
basics
~20 sUsually both survive, because they are not the same control. The gate rule is preventive and stops a non-compliant change before it lands; the nightly benchmark is detective and reports live systems afterwards. Neither covers the other's blind spot.
Your policy suite is green but no captured plan ever exercised one rule branch — how do you close that gap?
basics
~20 sEnumerate the rule's branches by reading the rule, not the corpus, then hand-write a fixture for each branch reality has not yet produced. Captured plans only contain what teams have already done, so whole conditions can sit untested behind a green suite.
An auditor asks which ruleset was live for each of last quarter's sweeps — what do you show?
basics
~20 sEach sweep record must carry the digest of the ruleset it loaded, and every published ruleset must still be retrievable by that digest so its rule text can be read back. A digest you can no longer resolve to content proves nothing.
Your rule requiring every image to descend from an approved base is correct, but a third of production images are vendor-built and carry no lineage metadata — do you ship it?
basics
~20 sNot as written. A rule is only shippable if every population it denies has a fix someone can perform, and nobody can add lineage metadata to a vendor's image. Narrow it to your own builds, or shelve it.
The renderer producing your policy input is changing shape — how do you version the contract and rules together?
basics
~20 sStamp a schemaVersion on the input document and have each rule declare which versions it can decide over. On an unknown version the rule refuses to decide and the gate blocks, so drift is loud.
A central security team wrote every policy rule and cannot maintain them. How do you re-home ownership?
basics
~20 sSplit authorship, ownership and operation. Move each rule to the domain team closest to the resource, transferred with its fixtures, its reason and its current denial rate, and with real authority to change it. Keep contractual rules central. Give unowned rules an expiry, not indefinite life.
Who approves widening a shared licence-policy rule's allowed list, and what does that silently re-open?
basics
~20 sWidening a shared parameter is a scope change, not an exception: it applies to every artifact reading that set, retroactively and silently. Approval belongs with the set's accountable owner plus the rule owner, on a computed delta of flipped decisions.
Your shared policy library ships 60 rules as one version. How do you roll one bad rule back everywhere?
basics
~20 sVersions are library-granular; a bad rule is not. Ship the off switch as configuration every enforcer reads at evaluation time so pinned consumers are covered too, then fix the rule forward in a new version. Never republish changed content under an existing version.
The synchronous gate's p99 latency budget is fixed and every team wants a rule in it — how do you allocate it?
basics
~20 sTreat the budget as a finite shared resource with an owner. Require a measured latency cost per proposed rule, admit it to the blocking path only when the prevention is worth the spend, and default the rest to out-of-band checks.
Every policy denial reaches your team as a ticket. How do you make denial triage self-service?
basics
~10 sRemove your team's monopoly on explanation: publish the evaluated input, version the rules so the deciding revision can be fetched, and ship one command that replays both and names the rule and field path.
Your policy engine major and your rule library both need upgrading. Which moves first, and why?
basics
~20 sNeither, as a big-bang. Find a rule-library version both engine majors accept, ship and bake that, then move the engine, then adopt new-engine-only constructs. Two small windows beat one large one, and you must name the window where enforcement is weakest.
showing 31–44 of 44