Skip to content

Policy

Policy provides model-aware, default-deny authorization for Domain abilities.

Generated facts

Layer
domain
Generated path
app/Pulsar/Domain/{Domain}/Policies/{Name}.php
Generator command
make:policy
Workflow method
None
Stability
Current manifest surface (Pulsar 0.4.1)

Canonical example

Generated src/stubs/policy-model.stub — canonical synchronized stub.

<?php

namespace {{namespace}};

use App\Models\User;

class {{name}}
{
    public function before(User $user, string $ability): ?bool
    {
        return $user->isAdmin() ? true : null;
    }
}

Responsibility

Policy owns the responsibility stated above; it must not absorb delivery, transaction, or unrelated cross-layer behavior.

Placement and dependencies

Keep this type in its generated Domain path. Domain is independent of delivery concerns; Infrastructure implements Domain-owned Contracts at its boundary.

Workflow and tests

Policy is consumed by the owning Domain or Service workflow and returns a delivery-neutral result. Test its direct contract, its rejected boundary cases, and the caller or callee that proves the rule in application flow.

Three pitfalls

  1. ❌ Prohibited: move this responsibility into a neighboring type merely because it is nearby.
  2. ✅ Correct: keep the generated placement and depend only on the documented layer direction.
  3. ✅ Correct: test the boundary through the caller and the return or side effect visible to its callee.

Related reading

Read architecture placement for shared rationale and follow this page’s related concept links for the adjacent responsibility.

Boundaries

❌ Prohibited: Do not make authorization depend only on an HTTP Request.

✅ Correct: Authorize every audience at its adapter boundary with the owning Policy or Gate.