Policy Violation Set Checks
Reported by candidates from Pinterest's online assessment. Pattern, common pitfall, and the honest play if you blank under the timer.
The detail that matters in Pinterest's September 2026 OA is the one in Example 3: a request that matches all three deny sets is still just one violation. This is Policy Violation Set Checks, and it's a hash-set lookup problem dressed up as access control. You get three deny lists and up to 100000 requests, each a [user, resource, action] triple. Return true when any field is blocked. It's easy if you stay calm and slow if you reach for nested loops. If you blank mid-assessment, StealthCoder runs invisibly as a safety net and hands you the pattern.
The problem
A request is [user, resource, action]. Three independent deny sets contain blocked users, blocked resources, and blocked actions. For every request, return true exactly when at least one of its three fields appears in the corresponding deny set. Return the decisions in input order. Function findPolicyViolations(blockedUsers: String[], blockedResources: String[], blockedActions: String[], requests: String[][]) → boolean[] Examples Example 1 blockedUsers = ["u2"] blockedResources = ["secret"] blockedActions = ["delete"] requests = [["u1","public","read"],["u2","public","read"],["u1","secret","read"],["u1","public","delete"]] return = [false,true,true,true] The last three requests each match one deny set. Example 2 blockedUsers = [] blockedResources = [] blockedActions = [] requests = [["a","b","c"]] return = [false] No deny rule applies. Example 3 blockedUsers = ["x"] blockedResources = ["r"] blockedActions = ["write"] requests = [["x","r","write"],["y","r","write"]] return = [true,true] A request remains one violation even when several deny sets match. Constraints 0 <= blockedUsers.length, blockedResources.length, blockedActions.length <= 100000. 1 <= requests.length <= 100000. Every request contains exactly three nonempty strings. Identifiers contain 1 to 40 visible ASCII characters. Each deny-set input contains unique values.
Reported by candidates. Source: FastPrep
Pattern and pitfall
The trick is to build three hash sets up front, one each for users, resources and actions. Then walk the requests once and check each field with O(1) membership. Total work is O(B + R), where B is the sum of the deny-list sizes and R is the number of requests. The pitfall is scanning the deny arrays for every request. With 100000 on both sides, that's 10^10 comparisons and a timeout. Other traps: empty deny lists (a set built from an empty array is fine, nothing matches), and the output order. Keep results aligned with the input index, so build the answer in a plain loop. Use OR logic, not a count, because multiple matches still yield one true. Strings are case-sensitive identifiers, so don't normalize them. If the setup slips your mind during the live OA, StealthCoder is the hedge that surfaces the three-set approach in seconds.
The honest play: practice the pattern, and have StealthCoder ready for the one you didn't see coming.
You can drill Policy Violation Set Checks cold, or you can hedge it. StealthCoder runs invisibly during screen share and surfaces a working solution in under 2 seconds. The proctor sees the IDE. They don't see what's behind it. Built for the candidate who saw this exact problem leak two days before his OA and wondered if anyone had a play.
Get StealthCoderRelated leaked OAs
You've seen the question.
Make sure you actually pass Pinterest's OA.
Pinterest reuses patterns across OAs. Built for the candidate who saw this exact problem leak two days before his OA and wondered if anyone had a play. Works on HackerRank, CodeSignal, CoderPad, and Karat.
Policy Violation Set Checks FAQ
How hard is Policy Violation Set Checks really?+
Easy. It's one hash-set concept applied three times. The only way to fail is brute-force scanning the deny lists per request, which times out at 100000 entries. If you know sets give O(1) lookup, you're done in about ten lines.
What's the trick to solving it fast?+
Load each deny list into its own set, then loop through requests once. For each triple, return blockedUsers.has(user) OR blockedResources.has(resource) OR blockedActions.has(action). Push the result in order. That's the whole solution.
Do I need to worry about requests matching multiple deny sets?+
No. Example 3 shows a request matching all three still returns a single true. Boolean OR handles it. Don't count matches or dedupe anything, since the output is one boolean per request.
What about empty deny lists?+
They're allowed, with lengths down to 0. An empty set just never matches, so those fields never trigger a violation. Example 2 covers this: everything empty, one request, result is [false]. No special-casing needed.
How should I prep for this in 48 hours?+
Don't grind new topics. Rehearse building sets from arrays and doing membership checks in your language of choice. Check the time complexity out loud. Then glance at similar lookup-style problems so the pattern feels automatic before the OA.