Policy as Code
also called Guardrail Policy
Expressing organisational rules as executable code evaluated automatically in pipelines and at admission, instead of as prose enforced by review.
A rule written in a standards document is enforced when a reviewer remembers it. The same rule written as code is enforced every time, including on the Friday deployment nobody reviewed. That difference is what turns governance from a meeting into a mechanism, and it is the single highest leverage move available to an architecture function that is losing ground to delivery pressure.
Typical rules: no storage bucket may be public, every resource carries a cost-centre tag, images must come from the approved registry and carry a signature, no container runs as root, production network rules may not allow ingress from anywhere.
Placement matters as much as the rule. The same policy can run in the editor, in CI on a plan, at admission in the cluster, and continuously against deployed resources. Earlier is faster feedback; later is actual enforcement, since CI can be bypassed and admission cannot. Serious programmes run the same policy at several points.
The adoption trap is going straight to blocking. Run new policies in warn mode first, measure how many existing resources violate them, and fix the backlog before enforcement — otherwise the first day of enforcement blocks every team at once and the policy gets an exemption instead of a fix.