OCOM Core Vocabulary

Policy

The OCOM Specification defines Policy as

A Policy is a governed set of rules that defines expected behavior or constraints applicable to one or more Objects.

Definition

A Policy is a governed set of rules that defines expected behavior or constraints applicable to one or more Objects. Policies express organizational intent independently of implementation technologies. Policies may be mandatory, recommended, or optional according to organizational governance.

Purpose

This document defines Policy within the OCOM Specification.

A Policy establishes governed rules that direct, constrain, or influence the behavior of Objects, operational activities, and organizational decisions.

Policies provide a consistent mechanism for enforcing governance across the OCOM ecosystem.

Business meaning

Policies ensure that operational activities remain aligned with organizational objectives, governance requirements, and regulatory obligations.

Rather than embedding rules within individual Objects, Policies provide reusable governance that can be consistently applied across multiple operational contexts.

Design principles

A Policy shall:

  • define governed rules
  • support organizational objectives
  • remain explicit
  • support traceability
  • support auditability
  • remain technology independent

Core characteristics

Every Policy shall define:

  • Identifier
  • Name
  • Purpose
  • Scope
  • Effective Date

A Policy may additionally define:

  • Description
  • Policy Owner
  • Applicable Objects
  • Constraints
  • Exceptions
  • Review Schedule
  • Expiration Date

Relationship to other specifications

Policy interacts with:

Policies define governing rules but do not perform operational activities.

Operational Memory retains Policies as part of the organizational context available when interpreting processes and decisions. Interpretation of a Policy's meaning and applicability remains the responsibility of the organization; Operational Memory preserves Policies but does not interpret them.

Compared with

Read as: OCOM term, the nearest concept in the other model, and how close they are. Similar means the two carry the same intent; Partial means they overlap but differ in scope or obligation; None means the other model has no counterpart. The verdicts are site-published editorial judgments, not normative.

Independence

The Policy specification does not prescribe:

  • policy engines
  • rule languages
  • workflow systems
  • implementation technologies

Organizations remain free to implement Policies using any compatible approach.

Policy Scope

Policies may apply to:

  • Objects
  • Registries
  • Workflows
  • AI Agents
  • Tools
  • Memory
  • Knowledge
  • Domains
  • Organizations

Organizations may define additional policy scopes.

Policy Categories

Examples include:

  • Governance Policy
  • Security Policy
  • Access Policy
  • Retention Policy
  • Classification Policy
  • Approval Policy
  • Evaluation Policy
  • Quality Policy
  • Compliance Policy

Organizations may define additional policy categories.

Policy Application

A Policy may apply to:

  • individual Objects
  • groups of Objects
  • Classifications
  • Relationships
  • Capabilities
  • operational contexts

Organizations shall define applicability rules.

Policy Lifecycle

Policies may progress through the following lifecycle:

  • Draft
  • Review
  • Approved
  • Active
  • Suspended
  • Retired

Organizations may extend the lifecycle.

Policy Enforcement

Organizations shall define how Policies are enforced.

Enforcement may be:

  • automated
  • manual
  • approval-based
  • advisory

Enforcement mechanisms are implementation-specific.

Policy Exceptions

Organizations may define controlled exceptions.

Exceptions should specify:

  • justification
  • approving authority
  • validity period
  • associated risks

Exception history shall be retained.

Governance

Policies shall be governed through:

  • ownership
  • approval
  • version management
  • periodic review
  • retirement

Governance activities shall remain traceable.

Auditability

Organizations shall preserve:

  • policy revisions
  • approval history
  • applicability history
  • exception history
  • retirement history

Audit records shall remain immutable.

Conformance

A compliant implementation shall:

  • define governed Policies
  • preserve Policy history
  • support Policy governance
  • maintain auditability
  • remain technology independent

Provenance

Governance records: CAND-003

VersionDateChange
0.120 July 2026Initial draft
0.123 July 2026Added Memory to Relationship to Other Specifications; clarified that Operational Memory preserves but does not interpret Policy, per Principle 11 (ADR CAND-003)

Recommended citation

OCOM Specification. Policy. META-POLICY-01. Version 0.1. https://ocom.uno/vocabulary/policy