AIDR registry authorization policy (Open Policy Agent / Rego)

The policy the AIDR registry runs for every operator action: roles and what each may do, which
actions need a hardware authenticator (AAL3), which need a second person (dual control), and
read-only and service-identity limits. Published as a reference for how a conforming registry
enforces separation of duties (AIAF, Agent Identity Assurance Framework, draft 0.1).

  aidr/authz.rego   the rules
  aidr/data.json    the role/capability matrix and its rationale, read by the rules

Run it:
  opa run --server --addr=127.0.0.1:8181 .
  curl -s localhost:8181/v1/data/aidr/authz/decision -d '{"input": {"action": "agent.revoke",
    "actor": {"id": "u1", "roles": ["security_officer"], "aal": 3}, "resource": {"org_id": "o1"}}}'

Tested with OPA 0.70. The directory name matters: OPA mounts data.json at data.aidr because the
file sits in aidr/.

Licensed under the Apache License, Version 2.0 (LICENSE).
