{
  "$schema": "https://json-schema.org/draft/2020-12/schema",
  "$id": "https://senscheck.dev/schema/policy.schema.json",
  "title": "SensCheck Governance Core policy configuration",
  "type": "object",
  "additionalProperties": false,
  "required": ["version", "default", "rules"],
  "properties": {
    "$schema": { "type": "string" },
    "version": { "const": 1 },
    "default": { "enum": ["DENY", "FAIL_CLOSED"] },
    "policyVersion": { "type": "string", "minLength": 1 },
    "verbAllowlist": { "$ref": "#/$defs/stringList" },
    "resourceAllowlist": { "$ref": "#/$defs/stringList" },
    "resourceDenylist": { "$ref": "#/$defs/stringList" },
    "rules": {
      "type": "array",
      "items": {
        "oneOf": [
          {
            "type": "object",
            "additionalProperties": false,
            "required": ["id", "when", "decision"],
            "properties": {
              "id": { "type": "string", "minLength": 1 },
              "description": { "type": "string" },
              "when": { "$ref": "#/$defs/condition" },
              "except": { "$ref": "#/$defs/condition" },
              "decision": { "const": "ALLOW" }
            }
          },
          {
            "type": "object",
            "additionalProperties": false,
            "required": ["id", "when", "decision"],
            "properties": {
              "id": { "type": "string", "minLength": 1 },
              "description": { "type": "string" },
              "when": { "$ref": "#/$defs/condition" },
              "decision": { "enum": ["DENY", "REQUIRE_APPROVAL"] }
            }
          }
        ]
      }
    }
  },
  "$defs": {
    "stringList": { "type": "array", "minItems": 1, "items": { "type": "string", "minLength": 1 } },
    "stringOrList": {
      "oneOf": [{ "type": "string", "minLength": 1 }, { "$ref": "#/$defs/stringList" }]
    },
    "riskLevel": { "enum": ["LOW", "MEDIUM", "HIGH", "CRITICAL"] },
    "condition": {
      "type": "object",
      "additionalProperties": false,
      "minProperties": 1,
      "properties": {
        "verb": { "$ref": "#/$defs/stringOrList" },
        "resource": { "$ref": "#/$defs/stringOrList" },
        "principalId": { "$ref": "#/$defs/stringOrList" },
        "principalType": {
          "oneOf": [
            { "enum": ["agent", "service", "human", "system"] },
            { "type": "array", "minItems": 1, "items": { "enum": ["agent", "service", "human", "system"] } }
          ]
        },
        "risk": {
          "oneOf": [
            { "$ref": "#/$defs/riskLevel" },
            { "type": "array", "minItems": 1, "items": { "$ref": "#/$defs/riskLevel" } }
          ]
        },
        "riskAtLeast": { "$ref": "#/$defs/riskLevel" },
        "environment": { "$ref": "#/$defs/stringOrList" },
        "time": {
          "type": "object",
          "additionalProperties": false,
          "minProperties": 1,
          "properties": {
            "notBefore": { "type": "string" },
            "notAfter": { "type": "string" },
            "hoursUtc": {
              "type": "object",
              "additionalProperties": false,
              "required": ["from", "to"],
              "properties": {
                "from": { "type": "integer", "minimum": 0, "maximum": 23 },
                "to": { "type": "integer", "minimum": 0, "maximum": 23 }
              }
            }
          }
        }
      }
    }
  }
}
