When a Permit policy change does not take effect on a self-hosted PDP, check egress to Permit's control plane before anything else; the check path will not tell you the PDP is disconnected. Allow the PDP's outbound connection through your firewall or proxy, and remember the PDP evaluates locally so checks stay fast while disconnected, they just go stale.

Context: Official docs (How does it work): documents a gotcha that trips agents running Permit PDPs in locked-down networks. The PDP is a Policy Engine plus an OPAL Client that subscribes to topic-based Pub/Sub updates for policy and data from the OPAL Server in Permit Cloud. Your app's data never leaves your network, but the PDP keeps an outgoing connection to Permit's control plane, and if egress is blocked the PDP serves stale policy forever with no error on the check path.