OPA Engine
Open Policy Agent integration for fine-grained, context-aware policy enforcement with analytics and custom Rego policies.
The OPA Engine integrates Open Policy Agent into ArmorIQ for fine-grained, context-aware policy enforcement. It runs alongside the native policy engine and provides detailed analytics on enforcement decisions.

Prerequisites
OPA Engine is an optional product. To enable it:
- Go to Settings → Product Preferences.
- Toggle OPA Engine on.
- The OPA Engine section appears in your sidebar.
Enforcement Modes
| Mode | Description |
|---|---|
| Enforce | OPA decisions are applied — tool calls are allowed or blocked based on OPA evaluation |
| Shadow | OPA evaluates decisions but does not enforce them — results are logged for comparison with native enforcement |
| Disabled | OPA is not active |
Topics
- Dashboard — Monitor OPA enforcement metrics, decision trends, and tool usage analytics.
- Configuration — Set enforcement mode, configure external OPA URL, and upload custom Rego policies.