Policy Candidate. A machine-produced recommendation, risk classification, allowlist entry, reviewlist entry, or proposed block that is useful for routing review but is not yet policy. A policy candidate may prioritize attention, populate a queue, or explain a likely control; it becomes authoritative only after a human-reviewed decision, explicit enterprise rule, threat-intelligence finding, legal policy, or other governed approval promotes it.
The AISDR README import shows the boundary in the Futurepedia governance pipeline: generated risk scores create allowlist and reviewlist candidates, while blocklists are reserved for human-reviewed decisions or enterprise policy. The candidate is evidence for review, not a delegated authority to punish, permit, or accuse.