docs← Back to article

Markdown for LLMs

OPA / Rego

The source Markdown for this article. Copy it into your assistant or download it as a text file.

Download this articlePlain text ↗
# OPA / Rego

**In short:** OPA answers "is this allowed?" for software systems; Arxo
answers "what follows from the norms?" for legal cases. On one admission
policy they meet — several independent grounds, an explicit refusal,
missing data, a structured verdict. This page is for platform engineers
who know Rego and wonder what a norms engine adds.

## What OPA is for

The Open Policy Agent decouples policy decisions from services: a sidecar
or library evaluates Rego policies over JSON input and returns a decision
document. Its strengths are mature delivery — versioned signed bundles,
decision logs with replay, compilation to a portable module — and a small
expressive core: incremental rule definitions, partial sets and objects,
defaults, rule chaining with alternatives, negation as failure, and
structured JSON output. Strict static checks, tests, formatting, and editor
tooling complete the loop.

## Where it meets Arxo

The shared task is one admission policy: several independent grounds for
admission, an explicit refusal, missing data in the request, a structured
verdict document naming grounds and refusal reasons, and a policy revision.
Both sides produce the same verdict shape from the same JSON cases, and the
server, log replay, and portable-module paths are explicitly deferred —
the comparison is about the policy language and its answers, not the
delivery machinery.

## Key differences

- **Rego is not true-or-false.** A missing attribute makes a rule silently
  not fire (the undefined value); complete rules are closed by explicit
  defaults. Arxo instead distinguishes absence of fact, explicit denial,
  and conflict as separate answers. Anyone mapping the two must carry that
  distinction, or the comparison silently shifts meaning.
- **Refusal is hand-written.** Allow and deny are ordinary rule names, not
  keywords; deny-overrides-assent is written out with negations,
  alternatives, and default-deny. Arxo declares the priority between
  competing grounds as its own construct with a named ground.
- **Two values for one rule is an evaluation error**, not a second answer:
  the engine reports a conflict at evaluation time. Kept versus resolved
  conflict is one of the sharpest semantic differences between the two
  systems — and a deliberate design choice on each side.
- **Delivery has no legal-time axis.** Bundle revisions version the policy
  text, but there is no notion of "the law as of this date" with editions
  and pinned sources. That absence is inferred from the docs and marked
  unconfirmed rather than asserted.

## A concrete scenario

The prepared experiment ships a file bundle with one structured verdict —
admitted or not, the grounds, the refusal reasons, the policy revision —
evaluated over fourteen JSON cases plus revision, parameter, and syntax
edits. The Arxo side mirrors the same verdict document; the contract pins
JSON-only inputs because a YAML decoding change in the studied version
would otherwise move the ground under the cases.

## Choosing and combining

Choose OPA when the consumer is software: services, pipelines, and
infrastructure that need fast versioned decisions with logs. Look to Arxo
when the consumer is a legal decision that must cite its edition, keep
conflicts visible, and refuse on missing facts rather than default them.
Combined, OPA can enforce the operational policy while Arxo holds the
normative reasoning behind the policy's content — with the verdict document
as the shared shape.

## Evidence and open questions

- Sources checked: September 2026 (policy language, debugging, testing,
  bundles, and release documentation at the pin, re-confirmed).
- Studied profile: OPA v1.21.0 with the current Rego default; a later
  patch release was noted and the pin kept.
- Basis: confirmed by documentation plus a prepared protocol; comparative
  run not performed. Expected bank outcomes are predictions, not results.
- Open: edition and legal-time semantics, and any performance claim —
  no timings are stated anywhere on this page.

## Sources and reproducible materials

- Companion page: [Coming from OPA / Rego](/comparisons/coming-from-opa/) — the same policy written in Arxo, side by side.
- Policy language and management docs:
  [Open Policy Agent documentation](https://www.openpolicyagent.org/)
- Release line: [github.com/open-policy-agent/opa](https://github.com/open-policy-agent/opa)