Pre-inference
Policy checks before a token is spent
Requests are matched against versioned policy-as-code (OPA/Rego or Cedar) keyed on actor, intent and data class. No matching allow rule, no inference — and the denial is ledgered with the policy version that produced it.