A Policy Enforcement Point (PEP) is where authorization checks are actually enforced—typically in your application code. It sends authorization queries to the PDP (Oso or Oso Cloud) and either allows or blocks access based on the result.