1. Create a project
In the console, create a project. Each project holds:
Projects hold exactly one policy. API keys are scoped to exactly one project.
2. Write a policy
Policies have three sections: metadata, rules, deployment.deployment.enabled: false — shadow mode.
3. Link policy to project
Attach the policy via the console, or via API:4. Issue a scoped API key
In the console, create an API key under the project. That key is bound to the project — every request made with it is evaluated against the linked policy.5. Send traffic through the policy surface
Point your client at/policy/* (not /v1/*) so policy evaluation and metadata injection happen:
6. Observe, then enforce
Let shadow mode run. Review decisions in the console or via your configured connector. When the allow/refuse rate looks right, flipdeployment.enabled: true and ramp percentage from 10 → 100 using canary mode.