Policies
Learn how to create and enforce Harness Policy As Code (OPA) policies for Feature Management & Experimentation (FME) feature flags and definitions.
Harness Policy As Code lets FME administrators define governance rules that are automatically evaluated whenever feature flags or feature flag definitions are created, updated, deleted, or archived. Policies are authored in Rego and evaluated using Open Policy Agent (OPA).
Harness provides out-of-the-box policies for Feature Management & Experimentation (FME). These policies cover common governance requirements across feature flags, environments, and segments.
Feature Flags
Naming Convention, Required Tags, Team Ownership Required
Feature Flag Definitions
Validation Rules
Environments
Naming Convention, Production Requires Approvals
Segments
Naming Convention
Segment Definitions
Validation Rules, Exclude High Priority Users
All policies are evaluated on On Save events across these entities. Policies apply across feature flag lifecycle, rollout configuration, targeting logic, and environment governance controls.
Prerequisites
Familiarity with Harness Policy As Code concepts such as policies, policy sets, and enforcement.
You need the Governance Policies and Governance Policy Sets permissions to create and enforce policies. The built-in FME Administrator role includes these permissions, or you can assign them through a custom role.
Policies are written in Rego. If you're new to Rego, see the Open Policy Agent documentation.
Input payload reference
When a policy is evaluated, Harness sends an input payload to OPA containing the entity data and metadata. The payload structure depends on the entity type.
Access Harness policies
When you navigate to the Policies page from Project, Account, or Organization Settings, you can manage policies, policy sets, and evaluations across the following tabs.
The Overview tab displays a high-level view of policy health across your project, account, or organization. This includes charts for policy evaluations, summary counts for policy sets and total evaluations, and the total number of policies.

Click the dropdown menu to view the policy health in the Last 24 hours, Last 7 days, and Last 30 days. Use this view to understand how policies are performing and whether violations are increasing or decreasing.
The Policies tab displays a list view of individual policies. To create a policy, click + New Policy.

Each row represents a single policy and includes the following information:
Policy
Name of the policy
Policy Store
Inline or Remote (Git-backed)
Referenced Policy Sets
Number of policy sets using the policy
Created At
Policy creation timestamp
Last Modified
Most recent update
Use the search bar to search for policies by name, and the dropdown menu to sort policies using filters such as Last Updated, A-Z, 0-9, or Z-A, 9-0. To manage your policies, click on the kebab menu (⋮) in a policy and select Edit or Delete.
The Policy Sets tab shows a list view of policy sets, which group one or more policies and define enforcement behavior. To create a policy set, click + New Policy Set.

Each row represents a single policy set and includes the following information:
Policy Set
Name of the policy set
Environment
Environment where the policy set applies (for FME, this is Harness)
Action
Trigger event (for FME, this is On Save)
Enforced
Whether enforcement is enabled
Entity Type
Type of entity (Feature Flag, Feature Flag Definition, Environment, Segment, Segment Definition )
Created At
Creation timestamp
Last Modified
Most recent update
Use the search bar to search for policy sets by name, and the dropdown menu to sort policy sets using filters such as Last Updated, A-Z, 0-9, or Z-A, 9-0. To manage your policy sets, click on the kebab menu (⋮) in a policy set and select Edit or Delete.
The Evaluations tab provides a list view of individual policy evaluations, allowing you to audit policy enforcement results.

You can filter evaluations using the time range dropdown menu (for example, Last 7 days). Each evaluation includes the following information:
Entity
Name of the evaluated entity
Entity Type
Type of entity (Feature Flag, Feature Flag Definition, Environment, Segment, Segment Definition )
Execution
Internal execution identifier
Evaluated On
When the evaluation occurred
Action
Trigger event (for FME, this is On Save)
Status
Evaluation result: Success, Failed, or Warning
This view is useful for troubleshooting failed saves and validating that policies are being enforced as expected.
Create and enforce a policy
To create a policy:
From the Harness FME navigation menu, click on Project, Account, or Organization Settings.
Under Security and Governance, select Policies. This directs you to the Overview tab which displays overall policy health over a selected time range.
Navigate to the Policies tab and click + New Policy. Optionally, you can import a policy from Git by clicking the dropdown menu and selecting Import from Git.
Enter a name for the policy and select the setup option:
Inline to author the policy in the Harness editor.
Remote to reference a Rego policy stored in a Git repository. Select a connector, repository, branch, and Rego path, then click Apply.
This opens the Policy Editor view, where you can author your own policy or use an out-of-the-box sample.

Policy editor view The editor includes a code editor for writing or modifying Rego, a Testing Terminal tab to validate policy behavior, and a Library tab containing sample policies.

FME policy library tab with sample policies Test the policy by opening the Testing Terminal tab.
Click Select Input.
Choose the appropriate inputs, including the entity type, organization, project, and action (On Save). Then, select an entity from the list of results.

Select input for policy testing Click Apply, then click Test. Review the output to confirm the policy behaves as expected.
Click Next: Enforce Policy.
Configure the following enforcement settings:
Scope: Select the appropriate scope, for example:
Account.Trigger event: Select On Save.
Severity:
Warn and Continue: Violations generate a warning, but the entity is saved.
Error and Exit: Violations block the save operation.
Click You're all set! to save and enforce the policy.
Add the policy to a policy set
Once you've created an individual policy, you must add it to a policy set before you can apply it to your feature flags. Policy sets allow you to group policies and configure where they will be enforced.
To add a policy set:
Navigate to the Policy Sets tab.
Click + New Policy Set.
In the Overview section, enter a name and optionally, include a description.
Select the entity type that this policy set applies to: Feature Flag, Feature Flag Definition, FME Environment, FME Segment, or FME Segment Definition.
Select On Save as the trigger event.
Click Continue.

New policy set configuration In the Policy evaluation criteria section, click + Add Policy.
Select a policy applicable to the chosen entity type (feature flag, environment, or segment).

Add policy to a policy set To the right of the policy, select Warn and Continue or Error and Exit.
Warn and Continue: If a policy isn't met when an entity is evaluated, you receive a warning but the entity is saved.
Error and Exit: If a policy isn't met when an entity is evaluated, you receive an error and the entity is not saved.
Click Apply.
To add an additional policy, click + Add Policy. When you're done adding policies to a policy set, click Finish.

Policy set with policies added In the Policy Sets list, click the Enforced checkbox for the policy set you created.

Enforced checkbox for policy set
How policies are evaluated
Policies are evaluated whenever a Feature Flag, Feature Flag Definition, FME Environment, FME Segment, or FME Segment Definition entity is created, updated, deleted, or archived. The input payload sent to OPA includes an entityMetadata.changeTrigger field (create, update, delete, or archive) so you can write policies that apply to specific change types.
An FME Feature Flag policy is evaluated when you change a feature flag's metadata. Examples of changes that trigger evaluation:
Creating a new feature flag
Updating a flag's name, description, tags, or metrics
Archiving or deleting a feature flag
An FME Feature Flag Definition policy is evaluated when you change a feature flag's targeting configuration in a specific environment. Examples of changes that trigger evaluation:
Adding or modifying targeting rules
Changing rollout percentages or traffic allocation
Updating the default treatment
Killing or restoring a flag in an environment
An FME Environment policy is evaluated when you create or modify environments in FME Settings. Examples of changes that trigger evaluation:
Creating a new environment
Updating the environment type
Modifying approval requirements or approvers
Updating data export permission settings
A Segment policy is evaluated when you create or update a segment. Examples of changes that trigger evaluation:
Creating a new segment
Updating the segment name
Modifying segment descriptions, tags, or owners
A Segment Definition policy is evaluated when you change a segment's definition or targeting logic. Examples of changes that trigger evaluation:
Adding or removing users in a segment
Defining or modifying rule-based conditions
On success, the change is applied. On failure, the result depends on the severity you configured:
Warn and Continue: The change is applied, but you receive a warning message.
Error and Exit: The change is blocked, and you receive an error message.
Manage policy evaluations
Navigate to the Evaluations tab to view all successful, warning, and failed policy set evaluations. Use the Type dropdown menu to filter by entities, and the Action dropdown menu to filter by On Save events.

Use the Status dropdown menu to filter evaluations by Success, Failed, or Warning. You can also use the time range selector to switch to a custom time range or a preset such as the past week, past month, or past three months.

Click on an evaluation in the list to access the policy set that was evaluated. You can then click into the policy set details and see associated policies, or click into the policy definition itself.

From here, you can review which policies were applied and their evaluation results.

From here, you can review the Rego logic that was evaluated and update it if needed.
See also
Last updated
Was this helpful?