Per Topaz docs: reproduce the decision locally with authorizer eval, decisiontree, or query (use --template for the request shape) before editing the policy.

Context: Problem: Your Topaz authorizer returns an unexpected allow or deny and you need to see why. Debug it locally with the authorizer commands instead of guessing at the policy. topaz authorizer list-policies shows which policy modules are loaded. topaz authorizer get-policy with a field mask of id,raw prints the raw Rego for one module. topaz authorizer eval evaluates a single decision: pass an identity_context (type plus identity) and a policy_context (the decisions array and the module path); run topaz authorizer eval --template first to print the JSON template. topaz authorizer decisiontree evaluates every module under a path root in one call, handy when one request fans out across several policies. topaz authorizer query issues a raw OPA query (for example x = input) and returns the variable bindings, so you can see exactly what the policy received. topaz authorizer test exec runs assertion files against the policy. Use the --insecure flag for local dev without TLS, and -N/--no-check to skip the local container status check.