This is related to the policy store feature https://github.com/step-security/harden-runner/issues/217. As of now, any user in the org where the app is installed can view and modify policy, but we do not have audit log of changes.