How do you implement your User Policy

I’d start here: http://www.postfix.org/ADDRESS_VERIFICATION_README.html

and: http://www.postfix.org/header_checks.5.html

This is for Zimbra, but it is about postfix: https://wiki.zimbra.com/wiki/Enforcing_a_match_between_FROM_address_and_sasl_username_8.5 (This might not be what you need, but could possibly help point you in the right direction.