# Put policy in the graph.

> Design governance as visible operational context for tools, connectors, data, environments, approvals, and consequential agent requests.

Canonical: https://rangoon.ai/product/policies/

Status: In active development. Product screenshots are design previews with illustrative data. No general availability is implied.

## Policy belongs near capability

Policy requirements can be associated with agents, skills, workflows, connectors, environments, data classes, and deployment targets.

### Concrete controls

Planned controls include tool access, sensitive data, external communication, infrastructure mutation, financial operations, secrets, and time windows.

## Treat changes as operations

The intended lifecycle is draft, diff, simulate, review, approve, stage, roll out, observe, and roll back.

### Impact before rollout

A policy change should reveal affected capabilities, changed approvals, exceptions, and simulation evidence.

## A foundation, not a claim

Rangoon is designed around LNSAT for execution authorization and evidence, with planned policy-engine adapters alongside it.

### Integration honesty

OPA, Cedar, and other policy-engine integrations are not claimed as shipped.


## More information

- [Documentation index](https://rangoon.ai/llms.txt)
- [AI access and policies](https://rangoon.ai/ai/)
- [Source repository](https://github.com/hypler-dev/rangoon)
