Waiver / Exception Flow for OPA Policy Evaluation Failures
S
Solid Bird
We would like to request a waiver (exception) workflow for OPA policy evaluation failures, similar to the existing waiver flow available for Security Test failures in Harness.
Currently, when an OPA policy evaluation fails, the pipeline execution is blocked with no built-in mechanism to request an exception. In real-world scenarios, certain policy violations may be acceptable temporarily (for example, during migrations, emergency fixes, or known-risk deployments), but there is no governed way to proceed.
Requested Feature:
Introduce a waiver mechanism for OPA policy failures that allows:
Users to request a waiver when an OPA evaluation fails
Approval by authorized reviewers (e.g., platform, security, or governance teams)
Ability to resume or re-run the pipeline after waiver approval
Optional metadata such as waiver reason, expiry date, and scope (pipeline, project, org, policy, etc.)
Log In