Skip to main content

policy-pattern

A small, embeddable ReBAC authorization engine for Python, inspired by Google Zanzibar.

Test Pipeline Lint Pipeline Coverage Pipeline Package Version Supported Python Versions

policy-pattern is a standalone Python library for relationship-based access control (ReBAC). It models authorization as relationships between subjects and objects and evaluates those relationships through composable authorization rules.

  • No authorization server
  • No required framework
  • No required database
  • No network hop

The library is designed to be embedded directly into Python applications that need richer authorization semantics than traditional role-based access control.

Status: v1 is code-complete — model, compile(), the storage port, MemoryTupleStore, and the Evaluator all exist and are tested.

See Architecture § Scope for what's planned (v1.x/v2) and unscheduled ideas.


Table of Contents


Example

model = Model()
model.types["document"] = Type(
    name="document",
    relations={
        "owner": Relation(allowed_subject_types=("user",)),
        "parent": Relation(allowed_subject_types=("folder",)),
    },
    permissions={
        "viewer": Union(left=Reference(name="owner"), right=TupleToUserset(tupleset="parent", computed="viewer")),
    },
)
compiled = model.compile()

evaluator = Evaluator(model=compiled, store=store)
evaluator.check(alice, "viewer", document_42)

viewer here means "the document's own owner, or the owner of whatever folder it lives in" — a document under folder:engineering inherits access from that folder without copying a permission onto every document.

See the Usage Guide for the full, runnable walkthrough — every rewrite operator, nested groups, EvaluationBudget, and error handling.


Documentation

The repository uses specifications and architecture documents as part of the implementation contract — they describe what must be true, independent of any one adapter's implementation.

docs/
├── README.md        — documentation index, start here
├── usage/README.md  — worked examples for every rewrite operator, budgets, error handling
├── architecture.md  — the model shape, compile(), the storage port, the evaluator, and scope/roadmap
├── semantics.md     — the storage contract every TupleStore adapter must satisfy
└── errors.md        — the PPxxx error code ranges and what each one means

Start with the Usage Guide to see the library working end to end, then Architecture to understand why the model is shaped the way it is.


Contributing

We love community help! Before you open an issue or pull request, please read:


License

Licensed under the Apache License 2.0.


References

The design is influenced by authorization systems and literature including:

policy-pattern is an independent project and is not an implementation of, or affiliated with, those projects.

Metadata

Release files for policy-pattern 0.1.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for policy-pattern 0.1.1
File Size Uploaded
policy_pattern-0.1.1.tar.gz 25.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for policy-pattern 0.1.1
File Interpreter ABI Platform
policy_pattern-0.1.1-py3-none-any.whl Python 3 none any Details

Total release size: 62.6 kB

Release files / policy_pattern-0.1.1.tar.gz

Download URL policy_pattern-0.1.1.tar.gz
Size 25.6 kB
Tags Source
SHA-256 checksum
How to use checksums
cd30c4c6b7aaa103480a230a8337dd4af743aa72ed5e7be4f6cfdc2489e9079a
BLAKE2b-256 checksum
How to use checksums
cd2d016e555f78c55edddabdb63005a4f88b361e840508563b44e0b09ceb855a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release files / policy_pattern-0.1.1-py3-none-any.whl

Download URL policy_pattern-0.1.1-py3-none-any.whl
Size 37.0 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cd9b7b55c195ae2193fc4136b104500cffd1dca911f7c2204a2fda3bc98209ed
BLAKE2b-256 checksum
How to use checksums
68925d5840be938cf0255e05d57702e8cb0a499bd2e031aaf80c0ea752fae8a4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 2, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.2

2 release files

This release

0.1.1 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page