how it works
What the gateway knows about a packet, how it decides, and why that shapes what a policy can say.
A gateway proves who it is with a certificate issued at enrolment. A person proves who they are with a session from Command Center or an API key. These never meet: a gateway cannot call the tenant API, and a person cannot open a control stream.
On the datapath, identity is resolved by looking a packet’s address up in a table the kernel holds. The lookup is exact: the table is keyed on a single 32-bit address, so it answers "which endpoint is this" for an address it has been told about, and nothing for one it has not.
Everything a policy can express follows from that. A rule names hosts because a host is what the table can hold. A prefix is not a key it can store, which is why a rule naming one is refused at submission rather than compiled into something that matches less than it reads as.
This is a current limit, not a design position
Prefix matching is planned and is a change to the kernel data structure rather than to the policy language. Rules naming single hosts keep working unchanged when it lands. See Current limits.
Enforcement runs in eBPF programs attached to the kernel’s networking hooks, so a packet is accepted or dropped without a round trip through userspace and without an agent inside your workloads. Your applications are unmodified and unaware.