Highflame Policy - Python Package
Cedar policy engine and typed constants for the Highflame security platform. Ensures entity/action consistency across all Highflame services.
Features
- 🔒 Cedar Policy Evaluation - Wraps
cedarpywith Highflame-specific types - 📝 Typed Constants - Auto-generated entity types, actions, and context keys (prevents typos!)
- 🔄 Cedar Parser - Convert Cedar text to structured PolicyRule JSON for UI editing
- ✅ Schema Validation - Validate policies against embedded Cedar schemas
- 🎯 Service-Specific Schemas - Overwatch (Guardian) and Palisade schemas included
- 🌐 Namespace Support - Generic support for namespaced entities and actions
Installation
pip install highflame-policy
Quick Start
Policy Evaluation (Palisade Example)
from highflame_policy import (
PolicyEngine,
EntityType,
ActionType,
schemas,
)
from highflame_policy.schemas import PalisadeContextKey
# Create engine with Palisade schema
engine = PolicyEngine(schema=schemas.palisade_schema)
engine.load_policies_from_file("palisade_policy.cedar")
# Evaluate with typed constants (no typos!)
decision = engine.evaluate(
principal_type=EntityType.SCANNER,
principal_id="palisade",
action=ActionType.SCAN_ARTIFACT,
resource_type=EntityType.ARTIFACT,
resource_id="/model.safetensors",
context={
PalisadeContextKey.ARTIFACT_FORMAT: "safetensors",
PalisadeContextKey.SEVERITY: "HIGH",
PalisadeContextKey.ENVIRONMENT: "production",
},
)
if decision.is_denied():
print(f"Blocked by policies: {decision.determining_policies}")
Service-Specific Schemas
from highflame_policy import PolicyEngine, schemas
from highflame_policy.schemas import OverwatchContextKey
# Use Overwatch (Guardian) schema for IDE security
engine = PolicyEngine(schema=schemas.overwatch_schema)
engine.load_policies(policy)
decision = engine.evaluate(
principal_type="Overwatch::User",
principal_id="mcp_client",
action='Overwatch::Action::"call_tool"',
resource_type="Overwatch::Tool",
resource_id="shell",
context={
OverwatchContextKey.THREAT_COUNT: 3,
OverwatchContextKey.TOOL_NAME: "shell",
},
)
Cedar Parser (Text → JSON)
from highflame_policy import parse_cedar_to_rules
cedar_text = '''
@id("allow-read")
permit(
principal is User,
action == Action::"read_file",
resource is FilePath
)
when { context.environment == "production" };
'''
result = parse_cedar_to_rules(cedar_text)
for rule in result.rules:
print(f"Rule: {rule['id']}, Effect: {rule['effect']}")
# Use in UI for editing
Detector Contract — which detector produces which attribute
detectors.json ships with the package, resolved, for every service that declares
a detector spec (ai_gateway, guardrails, overwatch, sentry).
from highflame_policy import producers_of, attributes_of, spec_version
producers_of("guardrails", "pii_detected") # ['pii_regex', 'pii_model']
producers_of("guardrails", "injection_score") # semantic field → every contributor
attributes_of("guardrails", "secrets") # ['contains_secrets', 'secret_types', ...]
spec_version("guardrails") # the contract this package was built against
Why it matters: a running Shield reports the detectors it registered; this reports what the spec declares. Bugs live in the difference — a detector emitting a key no product admits, or two detectors owning one key. Validating against this catches a wrong attribute name before it ships, instead of reading nothing at runtime.
producers_of returns [] for a field with no producer, which is a real state
rather than an error: identity, request metadata and cross-detector aggregates are
declared detector-less. Check framework_fields(service) to tell those apart from
a genuine gap.
Available Constants
Entity Types (17 total)
EntityType.USER,EntityType.AGENT,EntityType.SCANNER,EntityType.SERVICEEntityType.ARTIFACT,EntityType.TOOL,EntityType.SERVER,EntityType.FILE_PATHEntityType.MODEL,EntityType.REPOSITORY,EntityType.PACKAGE- And more...
Actions (38 total)
ActionType.SCAN_ARTIFACT,ActionType.CALL_TOOL,ActionType.LOAD_MODELActionType.PROCESS_PROMPT,ActionType.PROCESS_RESPONSEActionType.READ_FILE,ActionType.WRITE_FILE,ActionType.DELETE_FILEActionType.HTTP_REQUEST,ActionType.EXECUTE_CODE- And more...
Context Keys (Service-Specific)
Overwatch (Guardian) Context:
from highflame_policy.schemas import OverwatchContextKey
# 20+ context attributes for IDE security
OverwatchContextKey.THREAT_COUNT
OverwatchContextKey.TOOL_NAME
OverwatchContextKey.USER_EMAIL
OverwatchContextKey.SOURCE
# And more...
Palisade Context:
from highflame_policy.schemas import PalisadeContextKey
# 15+ context attributes for ML security
PalisadeContextKey.ENVIRONMENT
PalisadeContextKey.SEVERITY
PalisadeContextKey.ARTIFACT_FORMAT
PalisadeContextKey.PICKLE_EXEC_PATH_DETECTED
# And more...
Service-Specific Schemas
Overwatch (Guardian) - IDE Security
from highflame_policy import PolicyEngine, schemas
from highflame_policy.schemas import OverwatchContextKey
# Schema: schemas.overwatch_schema
# Context: schemas.overwatch_context (JSON metadata for UI)
# Namespaced entities and actions
engine = PolicyEngine(schema=schemas.overwatch_schema)
decision = engine.evaluate(
principal_type="Overwatch::User",
principal_id="claude-code-user",
action='Overwatch::Action::"call_tool"',
resource_type="Overwatch::Tool",
resource_id="bash",
context={
OverwatchContextKey.THREAT_COUNT: 0,
OverwatchContextKey.TOOL_NAME: "bash",
OverwatchContextKey.SOURCE: "claude-code",
},
)
Palisade - ML Supply Chain Security
from highflame_policy import PolicyEngine, schemas
from highflame_policy.schemas import PalisadeContextKey
# Schema: schemas.palisade_schema
# Context: schemas.palisade_context (JSON metadata for UI)
engine = PolicyEngine(schema=schemas.palisade_schema)
decision = engine.evaluate(
principal_type="Palisade::Scanner",
principal_id="palisade",
action='Palisade::Action::"scan_artifact"',
resource_type="Palisade::Artifact",
resource_id="/model.safetensors",
context={
PalisadeContextKey.SEVERITY: "HIGH",
PalisadeContextKey.ARTIFACT_FORMAT: "safetensors",
PalisadeContextKey.ENVIRONMENT: "production",
},
)
Input Validation
Protect against DoS attacks with built-in validation:
from highflame_policy import (
PolicyEngine,
EngineOptions,
ValidationLimits,
InputValidationError,
)
engine = PolicyEngine(
options=EngineOptions(
limits=ValidationLimits(
max_context_keys=200,
max_string_length=1_000_000,
max_nesting_depth=10,
)
)
)
try:
decision = engine.evaluate(...)
except InputValidationError as e:
print(f"Validation failed: {e}")
Why Typed Constants?
Without typed constants (error-prone):
context = {
"enviroment": "production", # Typo! Policy won't match
"severety": "HIGH", # Typo! Policy won't match
}
With typed constants (compile-time safety):
from highflame_policy.schemas import PalisadeContextKey
context = {
PalisadeContextKey.ENVIRONMENT: "production", # ✓ Autocomplete + type checking
PalisadeContextKey.SEVERITY: "HIGH", # ✓ Can't typo!
}
Architecture
This package wraps the official Cedar Python engine (cedarpy) with Highflame-specific types generated from the Cedar schema. All services use identical entity/action names, ensuring policy consistency.
┌─────────────────────────────────────────┐
│ schema/highflame.cedarschema │ ← Source of truth
│ (Cedar schema) │
└─────────────────────────────────────────┘
│
┌──────────┴──────────┐
│ Rust codegen tool │
└──────────┬──────────┘
│
┌───────────────┼───────────────┐
▼ ▼ ▼
Python Go TypeScript
cedarpy cedar-go cedar-wasm
│ │ │
▼ ▼ ▼
Palisade Guardrails Guardian
(scanner) (proxy) (IDE)
Related Packages
- Go:
github.com/highflame-ai/highflame-policy/packages/go - TypeScript:
@highflame/policyon npm - Rust:
highflame-policyon crates.io
Documentation
Full documentation: CLAUDE.md
License
Apache 2.0 - See LICENSE
Metadata
Release files for highflame-policy 2.2.45
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| highflame_policy-2.2.45.tar.gz | 295.0 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| highflame_policy-2.2.45-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 673.5 kB
Release files / highflame_policy-2.2.45.tar.gz
| Download URL | highflame_policy-2.2.45.tar.gz |
|---|---|
| Size | 295.0 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0f53f99e2548d00fa6296d744ecba2aa0b5bebcdcc0295d19013b15b07c715ce
|
|
BLAKE2b-256 checksum How to use checksums |
a74db349b8743eb330a979dbecd5056f49f7c4babfc1e07a9342f770c9938c29
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency logRelease files / highflame_policy-2.2.45-py3-none-any.whl
| Download URL | highflame_policy-2.2.45-py3-none-any.whl |
|---|---|
| Size | 378.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
8af6d8432999e42a6c49e39b1ebbf3b5064a299025518d636ba781689317be88
|
|
BLAKE2b-256 checksum How to use checksums |
b62f82fd4bf032b45a2e2dd193cf621ee91b29ccd3c9b6dc2abc84becc530359
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 27, 2026.
Transparency log