Activating a PolicySet compiles every active set into one snapshot (< 2 s at 10k rules), signs it with the ed25519 snapshot key, and stores it; the snapshot id is the content address of the CBOR blob, served over GET /v1/snapshot with an ETag. Distribution is pull-based, with a push nudge for idle sessions: a busy session adopts it via the detached post-decision pulse (a conditional GET throttled by the client's snapshotLagSeconds, default 30 s; a busy session lags at most one tool call plus that); an idle-but-connected session gets the policy-update push nudge and adopts in under 5 s, with the daemon tick (~30 s) as the fallback when no push reached it; new sessions and token refreshes fetch it at checkin. In every lane the blob is fetched and its signature verified before the session's snapshot id advances. An id alone would brick hooks. If the security layer is unreachable and no valid signed snapshot exists within the grace TTL (enterprise default 0, standalone 15 min), the client fails closed and denies everything governed. When a change must land in under 2 seconds, the lever is the session kill switch, not policy distribution.