Loading
Add organization-level Policy Store controller
What does this MR do and why?
Adds an organization-scoped home for the experimental Policy Store, mirroring the group-level Groups::Security::PolicyStoreController. Organizations are the target architecture for Policy Platform ownership/scoping; this gives the experiment an organization entry point while the group-level path remains available.
Everything is behind the security_policies_v2 experiment (feature flag + instance setting + the security_orchestration_policies license, via Organization#policy_store_experiment_active?).
- Navigation — a Policy store item in the organization Secure menu (
Sidebars::Organizations::Menus::SecureMenu), shown when the security dashboard or the Policy Store experiment is available. - Controller + routes —
Organizations::Security::PolicyStoreController(index/new/edit) under the org-scope; the edit route id is constrained to digits (/\d+/). JS route helpers regenerated. - Views —
index,new, andeditmount the shared Policy Store app on#js-policy-store, passingorganization_id,namespace_path,empty_list_svg_path, and the new/edit/list paths. - Frontend — the shared app renders the API-backed list (
fetchPolicies) onindexand the editor (step wizard) onnew/edit; navigation between them uses the backend-provided paths (visitUrl), and each row's edit path is derived from the list path and policy id. - Authorization — the
govern_policyresource:indexrequiresread_govern_policy,new/editrequireupdate_govern_policy, granted to organization owners and admins. Adds thecreate_govern_policyandupdate_govern_policydefinitions (the resource already carriesread/delete), giving it the full action-specific CRUD vocabulary.
References
- Policy Store: policy list page: https://gitlab.com/gitlab-org/gitlab/-/work_items/604312
- Policy Store: policy details and edit flow: https://gitlab.com/gitlab-org/gitlab/-/work_items/604308
- Policy Store: policy creation flow: https://gitlab.com/gitlab-org/gitlab/-/work_items/604307
- Group-level counterpart: !249445 (merged)
- Follow-up (action-specific enforcement): !249927 (merged)
- Epic: https://gitlab.com/groups/gitlab-org/-/work_items/22027
Screenshots or screen recordings
| List (empty state) | New (editor) |
|---|---|
![]() |
![]() |
Edit page (/…/1/edit):
How to set up and validate locally
- Enable the experiment:
security_policies_v2feature flag on, thepolicy_store_experiment_enabledinstance setting on, and an Ultimate (security_orchestration_policies) license. - As an organization owner/admin, open
/o/<org>/-/security/policy_store— the Secure sidebar shows Policy store; the list loads from the API. - Create new policy navigates to
/new(editor); a policy row links to/:id/edit; Cancel returns to the list. - Without the experiment, or as a non-owner, the routes return 404 and the item is hidden.
Visual verification
Verified on GDK (security_policies_v2 active, root on org default), 0 console errors on every state:
- List: the API fetch succeeds and the empty result renders the "No policies found" empty state; both create links point to
/o/default/-/security/policy_store/new. /new: the editor (step wizard) renders; no list fetch on the blank page.- Cancel: returns to the list via
visitUrl. /1/edit: the editor renders via the/\d+/route./not-a-number/edit: returns 404 — the numeric constraint rejects non-numeric ids.
Testing
- Frontend (
ee/spec/frontend/policy_store/components/app_spec.js,.../list/list_wrapper_spec.js): the list is API-backed with loading/error states and link navigation; the editor renders by initial view and resolves the policy by id; cancel navigates viavisitUrl. - Policy (
ee/spec/policies/organizations/organization_policy_spec.rb): the govern_policy read/write abilities role matrix. - Menu, request, and routing specs for the organization Policy Store.
- Local run: Jest 19/0, org RSpec suite 141/0, policy 15/0,
permissions:validateclean, ESLint/RuboCop/HAML-lint clean, plus the browser verification above.
MR acceptance checklist
Evaluate this MR against the MR acceptance checklist.
Edited by Alexander Turinske


