Hi Xavier,


As you said, a policy applies to all the sub-circles by default so no need to go deep in the holarchy, you just have to constraint/authorize the upper sub-circle (which is seen as a role from the sub-circle perspective, “tinted windows”, “black box”) and it would apply to all the sub-circles, without targeting anything specific.

If you could provide more context, that would help.