policy-pattern
A small, embeddable ReBAC authorization engine for Python, inspired by Google Zanzibar.
policy-pattern is a standalone Python library for relationship-based access control (ReBAC). It models
authorization as relationships between subjects and objects and evaluates those relationships through composable
authorization rules.
- No authorization server
- No required framework
- No required database
- No network hop
The library is designed to be embedded directly into Python applications that need richer authorization semantics than traditional role-based access control.
Status: v1 is code-complete — model,
compile(), the storage port,MemoryTupleStore, and theEvaluatorall exist and are tested.
See Architecture § Scope for what's planned (v1.x/v2) and unscheduled ideas.
Table of Contents
Example
model = Model()
model.types["document"] = Type(
name="document",
relations={
"owner": Relation(allowed_subject_types=("user",)),
"parent": Relation(allowed_subject_types=("folder",)),
},
permissions={
"viewer": Union(left=Reference(name="owner"), right=TupleToUserset(tupleset="parent", computed="viewer")),
},
)
compiled = model.compile()
evaluator = Evaluator(model=compiled, store=store)
evaluator.check(alice, "viewer", document_42)
viewer here means "the document's own owner, or the owner of whatever folder it lives in" — a document under
folder:engineering inherits access from that folder without copying a permission onto every document.
See the Usage Guide for the full, runnable walkthrough — every rewrite operator, nested
groups, EvaluationBudget, and error handling.
Documentation
The repository uses specifications and architecture documents as part of the implementation contract — they describe what must be true, independent of any one adapter's implementation.
docs/
├── README.md — documentation index, start here
├── usage/README.md — worked examples for every rewrite operator, budgets, error handling
├── architecture.md — the model shape, compile(), the storage port, the evaluator, and scope/roadmap
├── semantics.md — the storage contract every TupleStore adapter must satisfy
└── errors.md — the PPxxx error code ranges and what each one means
Start with the Usage Guide to see the library working end to end, then Architecture to understand why the model is shaped the way it is.
Contributing
We love community help! Before you open an issue or pull request, please read:
License
Licensed under the Apache License 2.0.
References
The design is influenced by authorization systems and literature including:
policy-pattern is an independent project and is not an implementation of, or affiliated with, those projects.
Metadata
Release files for policy-pattern 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| policy_pattern-0.1.0.tar.gz | 25.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| policy_pattern-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 62.6 kB
Release files / policy_pattern-0.1.0.tar.gz
| Download URL | policy_pattern-0.1.0.tar.gz |
|---|---|
| Size | 25.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1736e76d328019d78d17d116a80ba14dd6a53d1ad268c2a3a23256f5dfd3b933
|
|
BLAKE2b-256 checksum How to use checksums |
31a0ef2999fb311363cba2c57e7e894adabaef0bac82c157999bbf8118b1b317
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency logRelease files / policy_pattern-0.1.0-py3-none-any.whl
| Download URL | policy_pattern-0.1.0-py3-none-any.whl |
|---|---|
| Size | 37.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
272184eff1a7e666376d143b424c467463e2c22884004dda5db31ab87774425a
|
|
BLAKE2b-256 checksum How to use checksums |
276a322cc654f21e70047d29d60b8d6cde9c6d810fae819e96e0720acd85c777
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.
Transparency log