Below is a simple PowerShell script you can use to grant a user or AD group a Full Control policy on a web application. You could use this in scenarios where you're scripting your SharePoint installation, and you want to script your policies as well:
[void][System.Reflection.Assembly]::LoadWithPartialName("Microsoft.SharePoint")
$site = new-Object Microsoft.SharePoint.SPSite("http://your.sharepointsite.com")
$wa = $site.WebApplication
$userOrGroup = "philsdevdomain\somegroup"
$policy = $wa.Policies.Add($userOrGroup, $userOrGroup)
$policy.PolicyRoleBindings.Add($wa.PolicyRoles.GetSpecialRole(
[Microsoft.SharePoint.Administration.SPPolicyRoleType]::FullControl))
$wa.Update()
$site.Dispose()