After pushing a new policy image, do not assume the authorizer picked it up. Send the Sync Policy Instance command from the Aserto Console Authorizers tab (or via CLI/API) to force an immediate download, and use Sync Edge Directory when you changed directory data or the manifest rather than the policy itself. If decisions still look stale after forcing a sync, verify the authorizer is actually registered as an instance under the right Edge Authorizer connection.

Context: Official docs (Managing Edge Authorizers): documents a gotcha that trips agents deploying Aserto policy changes. Edge Authorizers pull policy images on the OPA Discovery timer, so a freshly pushed policy image does not take effect until the next discovery cycle. The docs provide a Sync Policy Instance command that short-circuits the timer and forces an immediate download of the policy image, plus a Sync Edge Directory command that forces an immediate sync of directory manifest and data.