Overview
Hexarch is a policy-driven API control plane that encodes authority as code. It enforces access, licensing, and auditability across time by turning approvals, expirations, and revocations into deterministic state transitions. Instead of tickets and manual reviews, the system keeps authority explicit and defensible for audits.
What was built
- Lifecycle engine for access proposals, approvals, issuance, enforcement, renewal, and revocation with invalid transitions rejected
- License and entitlement registry with automatic expiry, renewal, and revocation propagated to enforcement layers
- Continuous synchronization from authority to runtime enforcement so access always reflects current policy, not stale config
- Audit-ready evidence generation with immutable events and AI assistance for intent capture, change review, and summaries