Policy as code expresses organizational rules — who may do what, what blocks a deployment, which severity fails a build — as versioned, machine-evaluable artifacts rather than settings scattered across UIs. The policy gets code's virtues: review, history, testing, and consistent evaluation.
The properties that matter
- Versioned: you can state what the policy was on any past date.
- Central: one definition, evaluated everywhere it applies.
- Deterministic: same inputs, same verdict — no per-surface reinterpretation.
- Audited: changes carry author, review, and timestamp.
Policy as code vs policy in code
An if-statement inside a pipeline template is policy in code — embedded, forkable, invisible to governance. Policy as code separates the rule from the enforcement point: the rule lives centrally; enforcement points query it. That separation is what makes exceptions, rollouts, and audits tractable.

