- [ ] Policy DSL for risk thresholds - [ ] Auto-accept rules (e.g., dev env, no fix available) - [ ] Exception workflow with approval - [ ] Policy versioning and audit trail Success: Different policies for prod vs staging vs dev