Session lifetime, idle timeout, and login-failure lockout. Stored in /var/db/ogmaprotect/auth/auth.yaml and applied without a restart. A box with no policy uses the defaults (8 hour session, no idle timeout, 5 failures, 15 minute window). The system refuses a policy that could lock administrators out (too-short session or too-aggressive lockout).