Rego Policy Rules Are Only As Good As Whoever Writes Them
$NEWT Newton runs evaluations through Rego, a declarative policy language, and that's the part nobody's poking at yet. Someone still has to actually author these rules correctly, and Rego is notoriously easy to write technically valid logic that doesn't do what you think it does. If a vault curator or protocol writes a flawed policy, the zk proof will happily confirm that flawed policy was followed perfectly. Verification proves the rule executed as written, it says nothing about whether the rule itself was smart. That's a human error surface sitting right underneath all this cryptographic guarantee.
I want to see policy auditing tools before I trust curator written rules with real size. My exposure grows once there's a standard for reviewing Rego logic before it goes live on a vault. Proofs don't save you from bad policy design.
@NewtonProtocol $NEWT #Newt
$NEWT Newton runs evaluations through Rego, a declarative policy language, and that's the part nobody's poking at yet. Someone still has to actually author these rules correctly, and Rego is notoriously easy to write technically valid logic that doesn't do what you think it does. If a vault curator or protocol writes a flawed policy, the zk proof will happily confirm that flawed policy was followed perfectly. Verification proves the rule executed as written, it says nothing about whether the rule itself was smart. That's a human error surface sitting right underneath all this cryptographic guarantee.
I want to see policy auditing tools before I trust curator written rules with real size. My exposure grows once there's a standard for reviewing Rego logic before it goes live on a vault. Proofs don't save you from bad policy design.
@NewtonProtocol $NEWT #Newt
