Policy Administration Point (PAP)
The component where access policies are written, tested, managed and stored before a policy decision point applies them to requests. It authors the rules; it does not decide requests.
A policy administration point is where access policy is written and maintained. NIST SP 800-162, the guide to attribute-based access control, describes it as the interface for creating, managing, testing and debugging policies and storing them in a repository. The OASIS XACML standard uses the same term for the entity that creates policy. The PAP works before any request arrives: it sets the rules, and the policy decision point reads them when a request is evaluated.
It is one of four functional points commonly named together. The PAP authors policy, the policy information point supplies attributes, the decision point evaluates, and the policy enforcement point applies the result. Whoever controls the PAP shapes the decisions that follow, so changes made there are privileged actions that call for change management, separation of duties and audit. It should not be confused with the policy administrator of NIST SP 800-207, a zero trust component that acts on decisions while sessions run rather than authoring policy.
Exam relevance: a scenario is likely to ask where an access rule is defined, as distinct from where it is evaluated or enforced. Candidates are expected to place authoring at the PAP and to avoid mixing up the similar names PAP and PA.