WeAreDevelopers LIVE Oct 19, 2022

Policy as [versioned] code - you're doing it wrong

Chris Nesbitt-Smith

Writing rules in YAML isn't true policy as code. Stop breaking CI pipelines and start treating compliance as a visible, version-controlled software dependency.

Pause
Mute Enter Fullscreen
#1 about 5 min

Elevator pitch analogy for policy management

A fictional elevator scenario illustrates the pain points of policy enforcement among executives, product managers, and developers.

#2 about 4 min

Core promises of policy as versioned code

Treating policy as a versioned dependency enables faster updates, local compliance checks, and clear communication.

#3 about 4 min

Common pitfalls in implementing policy as code

Hiding security policies from developers leads to reverse-engineered constraints, broken deployments, and brittle case law exemptions.

#4 about 5 min

Managing policies exactly like standard software dependencies

Making policy source code visible and applying semantic versioning allows automatic compliance updates via standard continuous integration tools.

#5 about 5 min

Code demonstration using terraform and kubernetes

Evaluating semantic policy versions systematically across environments relies on localized validation and active admission controllers.

#6 about 4 min

Connecting policy rules directly to business risk

Policies must carry a clear risk narrative to prevent agile product teams from treating them as unnecessary friction.

#7 about 2 min

Addressing cultural resistance to compliance policy controls

Tangible risk communication prevents teams from viewing essential policies as bureaucratic hurdles.

#8 about 2 min

Evaluating risk scenarios across cheaper cloud providers

Using smaller cloud vendors instead of major players requires carefully understanding the organizational risk appetite.

#9 about 2 min

Row and cell level database encryption tradeoffs

Advanced database encryption methods must be proportional to risk due to the complexity of underlying key management and incident recovery.

#10 about 2 min

Presentation design and open source markdown tools

Markdown-based HTML presentation formats allow for rapid pacing and easy open source technical content generation.

#11 about 3 min

Usability and syntax challenges with rego and opa

Complex policy languages heavily prioritize performance over developer readability and require strict testing structures for validation.

#12 about 4 min

Mitigating software supply chain vulnerabilities with speed

Treating patch deployments like regular feature releases maintains rapid delivery while lowering third-party software supply chain dependency risks.

#13 about 5 min

Bridging engineering constraints and public sector governance

Brokering risk conversations in public systems involves translating abstract technology risks into concrete business trade-offs.

#14 about 4 min

Evaluating proportional security isolation and sandbox tactics

No environment is completely secure, meaning isolation tactics like sandboxing only represent one end of the overarching cost and risk spectrum.

#15 about 3 min

Expanding on policy as code methodology concepts

Contributing to open source thought leadership helps challenge current industry paradigms around infrastructure management and versioning.

Matching moments

1:22 min

Enforcing policy validations in continuous integration pipelines

Philipp Krenn · WWC 2023

7:07 min

Implementing programmatic policy checks with Open Policy Agent

Madhu Akula · LIVE

2:31 min

Enforcing compliance with guardrails and policy as code

Martin Reynolds Martin Reynolds · WWC 2025

4:48 min

Automating customized policy enforcement with open source tools

Noaa Barki · WWC 2022

3:01 min

Balancing coding productivity with enterprise data governance pipelines

Thomas Froment Thomas Froment · WWC Europe 2026

3:58 min

Exploring advanced security tooling and community dependency vetting

Niels Tanis Niels Tanis · WWC 2024

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Give the Agent a Budget, Not a Token

Sachin Malhotra

MTS @Anthropic

Sachin Malhotra
Open session

World Congress 2026 North America

On the Public Clock: Open-Source Defense When You're Not in the Club

Nicholas Muy

VP Engineering Platform and Security at Scrut.io

Nicholas Muy
Open session

World Congress 2026 North America

From Static Rules to Reasoning Platforms: Scaling Intelligent Canary Delivery in 2026

Daniel Oh

Senior Principal Developer Advocate

Daniel Oh
Open session

World Congress 2026 North America

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier
Open session

World Congress 2026 North America

Closing the Visibility Gap: Lessons from Safety Critical Agentic Systems

Vivek Pandit

Principal Engineer at Cadence

Vivek Pandit
Open session

World Congress 2026 North America

Agents Can't Iterate Against Tests That Lie

Rocky Warren

Senior Staff Software Engineer at Clipboard

Rocky Warren