ν.β E3 — Cedar policy authoring at scale — CLOSED 2026-05-04

Outcome

outcome-VALIDATED — kill condition NOT-MET on both legs.

Cedar production patterns survey (2026-05-04)

PatternStatusEvidence
AWS Verified PermissionsCONFIRMED production at scale700M auth/month <1ms, Stedi case study; Bedrock AgentCore Cedar GA 2026-03-03
cedar-for-agents (cedar-policy/ org)ALIVE, alpha-quality, NOT blocking20 stars, 8 forks, pushed 2026-04-29; alpha scaffold; additive MCP tooling
Postgres + Cedar extensionDOES NOT EXIST (0 GitHub results)Bespoke TEXT CRUD Phase-1 build task (~2d)
VSCode Cedar extensionMATURE v0.10.3 (2026-03-24)Tracks Cedar 4.9.1; 4.10.0 support imminent in v0.10.4

Scaling benchmark results (real measurements)

Environment: Cedar CLI 4.10.0 + cedar-policy-symcc 0.4.0 + cvc5 1.2.1 (validated binary) + WSL2

BenchmarkNMean (ms)Range (ms)N trials
check-parse1020.118.3–21.45
check-parse10022.820.9–25.65
check-parse100044.141.8–45.65
symcc equivalent (self-eq)1022.921.1–24.25
symcc equivalent (self-eq)5027.426.5–31.65
symcc equivalent (self-eq)10029.527.7–35.55
symcc never-errors (per-policy)122.421.2–23.55
symcc never-errors (10-policy loop)9.3 ms/policy1 timed run

Key caveat

Self-equivalence benchmarks (SET1 == SET1) resolve trivially. Non-trivially divergent 1000-policy set equivalence is NOT measured — Phase-1.5+ dedicated spike required before Phase-5+ architecture decisions.

6-agent loop Phase-1.5+ trigger framework

Five triggers for Cedar-at-scale Phase-1.5+ activation:

  • T1: Policy sets per tenant >20
  • T2: >1 agent generating Cedar policies per estate
  • T3: First faith-pillar partner firm onboarded
  • T4: Spike D4 trigger-event Cedar policies in production
  • T5: Partner firms require amendment equivalence guarantees

T-file location

/home/richardd/off-github/library/projects/inherit/T-spike-nu-beta-E3-cedar-policy-authoring-at-scale-2026-05-04.md