Definition
A Policy is a governed set of rules that defines expected behavior or constraints applicable to one or more Objects. Policies express organizational intent independently of implementation technologies. Policies may be mandatory, recommended, or optional according to organizational governance.
Purpose
This document defines Policy within the OCOM Specification.
A Policy establishes governed rules that direct, constrain, or influence the behavior of Objects, operational activities, and organizational decisions.
Policies provide a consistent mechanism for enforcing governance across the OCOM ecosystem.
Business meaning
Policies ensure that operational activities remain aligned with organizational objectives, governance requirements, and regulatory obligations.
Rather than embedding rules within individual Objects, Policies provide reusable governance that can be consistently applied across multiple operational contexts.
Design principles
A Policy shall:
- define governed rules
- support organizational objectives
- remain explicit
- support traceability
- support auditability
- remain technology independent
Core characteristics
Every Policy shall define:
- Identifier
- Name
- Purpose
- Scope
- Effective Date
A Policy may additionally define:
- Description
- Policy Owner
- Applicable Objects
- Constraints
- Exceptions
- Review Schedule
- Expiration Date
Relationship to other specifications
Policy interacts with:
ocom:Objectocom:Capabilityocom:Constraintocom:Contractocom:Registryocom:Classificationocom:Ownershipocom:Evaluationocom:Governanceocom:Memory
Policies define governing rules but do not perform operational activities.
Operational Memory retains Policies as part of the organizational context available when interpreting processes and decisions. Interpretation of a Policy's meaning and applicability remains the responsibility of the organization; Operational Memory preserves Policies but does not interpret them.
Compared with
Read as: OCOM term, the nearest concept in the other model, and how close they are. Similar means the two carry the same intent; Partial means they overlap but differ in scope or obligation; None means the other model has no counterpart. The verdicts are site-published editorial judgments, not normative.
- OCOM vs BPMN: Partial (Gateway condition / business rule)
- OCOM vs Process Model: Partial (Gateway condition / Business rule)
- OCOM vs ArchiMate: Partial (Requirement / Principle)
Independence
The Policy specification does not prescribe:
- policy engines
- rule languages
- workflow systems
- implementation technologies
Organizations remain free to implement Policies using any compatible approach.
Policy Scope
Policies may apply to:
- Objects
- Registries
- Workflows
- AI Agents
- Tools
- Memory
- Knowledge
- Domains
- Organizations
Organizations may define additional policy scopes.
Policy Categories
Examples include:
- Governance Policy
- Security Policy
- Access Policy
- Retention Policy
- Classification Policy
- Approval Policy
- Evaluation Policy
- Quality Policy
- Compliance Policy
Organizations may define additional policy categories.
Policy Application
A Policy may apply to:
- individual Objects
- groups of Objects
- Classifications
- Relationships
- Capabilities
- operational contexts
Organizations shall define applicability rules.
Policy Lifecycle
Policies may progress through the following lifecycle:
- Draft
- Review
- Approved
- Active
- Suspended
- Retired
Organizations may extend the lifecycle.
Policy Enforcement
Organizations shall define how Policies are enforced.
Enforcement may be:
- automated
- manual
- approval-based
- advisory
Enforcement mechanisms are implementation-specific.
Policy Exceptions
Organizations may define controlled exceptions.
Exceptions should specify:
- justification
- approving authority
- validity period
- associated risks
Exception history shall be retained.
Governance
Policies shall be governed through:
- ownership
- approval
- version management
- periodic review
- retirement
Governance activities shall remain traceable.
Auditability
Organizations shall preserve:
- policy revisions
- approval history
- applicability history
- exception history
- retirement history
Audit records shall remain immutable.
Conformance
A compliant implementation shall:
- define governed Policies
- preserve Policy history
- support Policy governance
- maintain auditability
- remain technology independent
Provenance
Governance records: CAND-003
| Version | Date | Change |
|---|---|---|
| 0.1 | 20 July 2026 | Initial draft |
| 0.1 | 23 July 2026 | Added Memory to Relationship to Other Specifications; clarified that Operational Memory preserves but does not interpret Policy, per Principle 11 (ADR CAND-003) |