Explain Rego decision
rego_explain_decisionEvaluate a Rego query with full tracing to return a structured trace and per-rule fired/not-fired summary, explaining why a policy decision was denied.
Instructions
Evaluate a Rego query with full tracing and return a structured trace plus per-rule fired/not-fired summary. Use this when you need to answer "why was this denied?" -- the agent reads the structured trace and narrates the cause without re-implementing the trace parser.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| input | No | Inline input document. | |
| paths | No | Policy / data file or directory paths. Each must be inside an allowed root. | |
| query | Yes | Rego query to evaluate, e.g. "data.example.allow". | |
| source | No | Inline Rego policy source. Optional: without `source` or `paths` the query runs on its own, which is enough to try a built-in or an expression. | |
| partial | No | Run partial evaluation rather than full evaluation. | |
| unknowns | No | Refs to treat as unknown during partial evaluation. | |
| inputPath | No | Path to a JSON input file. Mutually exclusive with `input`. | |
| v0Compatible | No | Read the policy as Rego v0 (`--v0-compatible`), the syntax OPA used before 1.0: rules without `if`, partial sets as `deny[msg] { ... }`. Needed for a policy that has not been migrated, which OPA 1.x otherwise refuses to load. Where the tool also takes a query, the query is read as v0 too, with the future keywords imported so `in`, `every` and `some x in` still work in it. | |
| strictBuiltinErrors | No | Treat builtin errors as fatal instead of returning undefined. |