The Margrave Policy Analyzer

Access-control policies, firewall configurations, hypervisor configurations, social-network privacy settings, ...

Modern computing systems are teeming with policies. Errors in policies can be embarassing, costly, and have legal consequences. But making mistakes is easy! Policies may be geographically distributed, encode complex dependencies, and interact with environments that change frequently. Enforcing an organization's security goals may require the cooperation of several policies in different languages and at different levels of abstraction.

How can a policy author gain confidence in their settings?

Margrave is a policy-analysis tool with several powerful capabilities:

