01 / What each boundary answers
Compare the decision, not the label.
Evaluates a policy request and returns a decision based on supplied attributes and rules.
Adds originating grants, delegation lineage, revocation state and correlated execution evidence as an architectural concern.
02 / Same operating case
Which request must be stopped?
A policy engine receives agent=finance and action=pay, but no originating invoice task or delegated limit.
Evaluation exercise
Send two identical policy-engine requests with different parent-grant states. If the engine receives no ancestry or revocation signal, the executor needs another trustworthy check.
03 / Architecture fit
How the controls can compose
A policy engine can be one component of an authority architecture; existing engines may support rich attributes and external data.
This is a system-design distinction, not a claim that policy vendors cannot model grants or evidence.
04 / Evidence
Prove the decision and the effect separately.
Preserve request, attribute provenance, policy version, decision, executor transaction and payment outcome.
Primary sources