Error of mem erroring Policies
Cedar.Thm.error_of_mem_erroringPolicies
Plain-language statement
Bridge from Response.erroringPolicies membership back to the evaluator: if a policy id appears in the erroring set produced by isAuthorized, then some policy in ps with that id genuinely errored on evaluation. Because policy ids need not be unique, this recovers a policy with the id, not necessarily a specific one.
Source project: Cedar Specification
Person-level attribution pending.