{
  "schema": "varexis-public-evidence-record/0.3",
  "generated_at_utc": "2026-10-06T23:09:49Z",
  "record_id": "VXI-EXT-OPA-04-v1",
  "record_kind": "external_reference",
  "title": "OPA: Management interfaces",
  "system": "Open Policy Agent",
  "evidence_family": "policy_enforcement",
  "index_status": "PUBLIC_SAFE_SOURCE_REVIEW",
  "evidence_state": "PRIMARY_DOCUMENTATION_REVIEW_ONLY",
  "canonical_question": "What do OPA's management interfaces cover?",
  "near_questions": [
    "Which OPA interfaces support policy management?",
    "Does OPA include a completed control plane automatically?",
    "How do policy bundles differ from decision logs?",
    "Can status telemetry prove that every decision was enforced?",
    "What should a buyer identify in an OPA management design?",
    "Do management APIs guarantee policy rollout success?",
    "Can a receipt link a decision to its bundle revision?",
    "What privacy review is needed for decision telemetry?",
    "Does discovery configuration validate the policy itself?",
    "How should missing logs limit an audit claim?",
    "What is required to review an OPA control plane claim?",
    "Which record distinguishes management APIs from an operating service?"
  ],
  "supported_claims": [
    {
      "claim": "OPA documents interfaces for policy bundles, decision logs, status and discovery configuration. Integrators configure or implement the surrounding management service; the interfaces alone are not a completed control plane.",
      "reliance": "DOCUMENTED_CAPABILITY_ONLY"
    }
  ],
  "not_demonstrated_claims": [
    "a deployed management service",
    "complete audit retention",
    "secure handling of every decision log"
  ],
  "public_summary": "OPA documents interfaces for policy bundles, decision logs, status and discovery configuration. Integrators configure or implement the surrounding management service; the interfaces alone are not a completed control plane.",
  "related_record_ids": [
    "VXI-EXT-OPA-01-v1",
    "VXI-EXT-OPA-02-v1",
    "VXI-EXT-OPA-03-v1"
  ],
  "source_review": {
    "source_type": "official_external_documentation",
    "source_title": "OPA Management APIs and Architecture",
    "source_url": "https://www.openpolicyagent.org/docs/management-introduction",
    "checked_on": "2026-10-07",
    "candidate_record_id": "VXI-EXT-OPA-04-v1",
    "candidate_record_sha256": "628e03f2dd223c1af7e977dbeea127d8ca6058a5139d982216670e594d204aea",
    "method": "Primary documentation reviewed for the published bounded statement.",
    "deployment_tested_by_varexis": false,
    "revalidation": "Recheck the primary source, version and deployment context before paid delivery."
  },
  "answer_policy": {
    "classification": "DOCUMENTED_WITH_DEPLOYMENT_BOUNDARY",
    "bounded_answer": "OPA documents interfaces for policy bundles, decision logs, status and discovery configuration. Integrators configure or implement the surrounding management service; the interfaces alone are not a completed control plane.",
    "required_buyer_context": "Bundle distribution, status reporting, logging configuration and the actual management service.",
    "missing_evidence": "A broader claim needs evidence matching the intended use. Payment does not upgrade the evidence state."
  },
  "private_boundary": "Raw logs, thresholds, private paths, source code, protected mechanisms and reconstruction-level details are excluded from public and paid delivery.",
  "paid_access_note": "The public answer and boundaries are free. Pay first, then email a concrete question for asynchronous manual review, receipt or scoped export. No fixed turnaround or automatic API access is promised.",
  "service_route": {
    "request_guide": "/varexis-index/request.html",
    "request_workflow": "/varexis-index/request-workflow.json",
    "service_id": "evidence_receipt",
    "service_routes_url": "/varexis-index/service-routes.json",
    "payment_required": true,
    "accepting_paid_requests": true,
    "operational_status": "PAID_ASYNC_MANUAL_FULFILMENT",
    "checkout_url": "https://buy.stripe.com/28EaEXaPe7bBdGLgXSdwc05"
  },
  "authority_boundary": "VAREXIS-INDEX informs evidence reliance. It does not provide advice, certification, deployment authority, security assurance, production approval, or guarantee.",
  "human_page": "/varexis-index/catalog.html#opa-management-interfaces",
  "machine_readable_record": "/varexis-index/records/opa-management-interfaces.json"
}
