W/respect to the comment "we should be able to state a policy without
worrying about the mechanism of interpretation of it", it depends upon what
you mean by "worry". I think that, once you are immersed in a particular
authorization model, it should be fairly easy to write policies for that
model but that, in general, you cannot write authorization policies in a
vacuum. Authorization policies only make sense in the context of an
authorization model and authorization models define (among other things) how
policies are evaluated/interpreted.