Markdown for LLMs
OPA / Rego
The source Markdown for this article. Copy it into your assistant or download it as a text file.
# OPA / Rego **In short:** OPA answers "is this allowed?" for software systems; Arxo answers "what follows from the norms?" for legal cases. On one admission policy they meet — several independent grounds, an explicit refusal, missing data, a structured verdict. This page is for platform engineers who know Rego and wonder what a norms engine adds. ## What OPA is for The Open Policy Agent decouples policy decisions from services: a sidecar or library evaluates Rego policies over JSON input and returns a decision document. Its strengths are mature delivery — versioned signed bundles, decision logs with replay, compilation to a portable module — and a small expressive core: incremental rule definitions, partial sets and objects, defaults, rule chaining with alternatives, negation as failure, and structured JSON output. Strict static checks, tests, formatting, and editor tooling complete the loop. ## Where it meets Arxo The shared task is one admission policy: several independent grounds for admission, an explicit refusal, missing data in the request, a structured verdict document naming grounds and refusal reasons, and a policy revision. Both sides produce the same verdict shape from the same JSON cases, and the server, log replay, and portable-module paths are explicitly deferred — the comparison is about the policy language and its answers, not the delivery machinery. ## Key differences - **Rego is not true-or-false.** A missing attribute makes a rule silently not fire (the undefined value); complete rules are closed by explicit defaults. Arxo instead distinguishes absence of fact, explicit denial, and conflict as separate answers. Anyone mapping the two must carry that distinction, or the comparison silently shifts meaning. - **Refusal is hand-written.** Allow and deny are ordinary rule names, not keywords; deny-overrides-assent is written out with negations, alternatives, and default-deny. Arxo declares the priority between competing grounds as its own construct with a named ground. - **Two values for one rule is an evaluation error**, not a second answer: the engine reports a conflict at evaluation time. Kept versus resolved conflict is one of the sharpest semantic differences between the two systems — and a deliberate design choice on each side. - **Delivery has no legal-time axis.** Bundle revisions version the policy text, but there is no notion of "the law as of this date" with editions and pinned sources. That absence is inferred from the docs and marked unconfirmed rather than asserted. ## A concrete scenario The prepared experiment ships a file bundle with one structured verdict — admitted or not, the grounds, the refusal reasons, the policy revision — evaluated over fourteen JSON cases plus revision, parameter, and syntax edits. The Arxo side mirrors the same verdict document; the contract pins JSON-only inputs because a YAML decoding change in the studied version would otherwise move the ground under the cases. ## Choosing and combining Choose OPA when the consumer is software: services, pipelines, and infrastructure that need fast versioned decisions with logs. Look to Arxo when the consumer is a legal decision that must cite its edition, keep conflicts visible, and refuse on missing facts rather than default them. Combined, OPA can enforce the operational policy while Arxo holds the normative reasoning behind the policy's content — with the verdict document as the shared shape. ## Evidence and open questions - Sources checked: September 2026 (policy language, debugging, testing, bundles, and release documentation at the pin, re-confirmed). - Studied profile: OPA v1.21.0 with the current Rego default; a later patch release was noted and the pin kept. - Basis: confirmed by documentation plus a prepared protocol; comparative run not performed. Expected bank outcomes are predictions, not results. - Open: edition and legal-time semantics, and any performance claim — no timings are stated anywhere on this page. ## Sources and reproducible materials - Companion page: [Coming from OPA / Rego](/comparisons/coming-from-opa/) — the same policy written in Arxo, side by side. - Policy language and management docs: [Open Policy Agent documentation](https://www.openpolicyagent.org/) - Release line: [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa)