Context policy checks provenance and authorization metadata after retrieval. Applications must also enforce tenant and ACL scope inside the retrieval query so unauthorized rows are never selected in the first place.
Usage
context_policy(
required_columns = c("document_id", "source"),
tenant_id = NULL,
tenant_col = "tenant",
principals = NULL,
acl_col = NULL,
trusted_sources = NULL,
source_col = "source",
allowed_trust_tiers = NULL,
trust_col = "trust_tier",
max_age_seconds = NULL,
timestamp_col = "updated_at",
authorize = NULL,
now = Sys.time,
show_stats = FALSE
)Arguments
- required_columns
Character vector of metadata columns that must exist and contain a value in every row.
- tenant_id
Optional scalar tenant identifier required for every row.
- tenant_col
Scalar name of the tenant column.
- principals
Optional character vector of subject or role identifiers.
- acl_col
Optional ACL column. Values may be character vectors, list column entries, or comma-separated strings.
- trusted_sources
Optional character vector of allowed source values.
- source_col
Scalar name of the source column.
- allowed_trust_tiers
Optional character vector of allowed trust tiers.
- trust_col
Scalar name of the trust-tier column.
- max_age_seconds
Optional non-negative maximum age in seconds.
- timestamp_col
Scalar name of the freshness timestamp column.
Optional function that receives a one-row data frame and returns
TRUEonly when the row is authorized.- now
Zero-argument function returning the current time. Override it for deterministic tests and examples.
- show_stats
Show construction time and available usage metrics.
Examples
admission <- context_policy(
required_columns = c("document_id", "source", "tenant"),
tenant_id = "tenant-a"
)
