# `verae-access-authz/policy` **Package:** `verae-access-authz` **Source:** `packages/verae-access-authz/src/policy.js` **Lines:** 99 ## What this module is Implementation module in `verae-access-authz`. The tables below are extracted from the source (signatures + JSDoc). ## Exports `POLICY`, `authorize` ## Types / interfaces / classes _None extracted._ ## Functions | Name | Parameters | Param types (JSDoc) | Returns | Calls (same file / helpers) | |------|------------|---------------------|---------|-----------------------------| | `prefixAllowed` | `allow, subject` | — | `unknown` | see Call graph | | `authorize` | `req` | — | `unknown` | see Call graph | | `deny` | `plane, subject, reason` | — | `unknown` | see Call graph | ## What it imports / requires - `./subjects.js` ## Call graph (identifiers invoked) `workers`, `freeze`, `web`, `prefixAllowed`, `some`, `endsWith`, `startsWith`, `authorize`, `parseAddress`, `deny`, `includes`, `mismatch` Each identifier is a call site in this file. Follow the import list to see the defining module; open that module’s MD for parameter and return types. ## Return values (how to read this) - HTTP route handlers return Express `res.json(...)` bodies (see route docs). - Zapier `perform` functions return a **single object** (creates) or an **array** (triggers/searches). - Pricing functions return integer **cents** on `Quote.totalCents`.