Hi Tony,
Including an XACMLPolicyAssertion in a WS-Policy instance is a way for a
service to declare its access control / authorization policy. It
describes a "requirement of a policy subject" - its authorization
requirement - so I think is a true assertion in the WS-Policy sense.
Clients can use this Assertion to determine what attributes or message
field values they would need to provide in order to access the service,
and ultimately whether they would be authorized to access the service.
Yes, you will be matching on the strong type