Some checks failed
		
		
	
	Docs CI / lint-and-preview (push) Has been cancelled
				
			- Added VulnTokenSigner for signing JWT tokens with specified algorithms and keys. - Introduced VulnTokenUtilities for resolving tenant and subject claims, and sanitizing context dictionaries. - Created VulnTokenVerificationUtilities for parsing tokens, verifying signatures, and deserializing payloads. - Developed VulnWorkflowAntiForgeryTokenIssuer for issuing anti-forgery tokens with configurable options. - Implemented VulnWorkflowAntiForgeryTokenVerifier for verifying anti-forgery tokens and validating payloads. - Added AuthorityVulnerabilityExplorerOptions to manage configuration for vulnerability explorer features. - Included tests for FilesystemPackRunDispatcher to ensure proper job handling under egress policy restrictions.
		
			
				
	
	
	
		
			2.0 KiB
		
	
	
	
	
	
	
	
			
		
		
	
	
			2.0 KiB
		
	
	
	
	
	
	
	
Policy Engine agent guide
Mission
Policy Engine compiles and evaluates Stella DSL policies deterministically, producing explainable findings with full provenance.
Key docs
- Module README
 - Architecture
 - Implementation plan
 - Task board
 - Secret leak detection readiness
 - Windows package readiness
 
How to get started
- Open ../../implplan/SPRINTS.md and locate the stories referencing this module.
 - Review ./TASKS.md for local follow-ups and confirm status transitions (TODO → DOING → DONE/BLOCKED).
 - Read the architecture and README for domain context before editing code or docs.
 - Coordinate cross-module changes in the main /AGENTS.md description and through the sprint plan.
 
Guardrails
- Honour the Aggregation-Only Contract where applicable (see ../../ingestion/aggregation-only-contract.md).
 - Preserve determinism: sort outputs, normalise timestamps (UTC ISO-8601), and avoid machine-specific artefacts.
 - Keep Offline Kit parity in mind—document air-gapped workflows for any new feature.
 - Update runbooks/observability assets when operational characteristics change.
 
Required Reading
docs/modules/policy/README.mddocs/modules/policy/architecture.mddocs/modules/policy/implementation_plan.mddocs/modules/platform/architecture-overview.md
Working Agreement
- 
- Update task status to 
DOING/DONEin bothdocs/implplan/SPRINTS.mdand the localTASKS.mdwhen you start or finish work. 
 - Update task status to 
 - 
- Review this charter and the Required Reading documents before coding; confirm prerequisites are met.
 
 - 
- Keep changes deterministic (stable ordering, timestamps, hashes) and align with offline/air-gap expectations.
 
 - 
- Coordinate doc updates, tests, and cross-guild communication whenever contracts or workflows change.
 
 - 
- Revert to 
TODOif you pause the task without shipping changes; leave notes in commit/PR descriptions for context. 
 - Revert to