INVARIANCE | Arc
MenuClose
About Invariance

Organizational authority for consequential work.

Invariance develops Authority Control, Enterprise Authority Control software. It applies the organization’s established authority to consequential results before they take effect. Each determination creates a durable authority record.

Foundational principle

Software should preserve the authority behind consequential action.

Technology can expand the ability to act without expanding organizational authority. The organization should be able to identify the proposed result, who initiated it, and the authority that applied.

Capability can expand. Organizational authority should remain explicit, attributable, and enforceable.

Research foundation

Technology changes. Organizational authority must remain current.

Authority Control grew from sustained work across cognitive science, organizational theory, cybersecurity, organizational accountability, and human-AI collaboration.

That work examined how organizations keep authority and accountability connected to consequential work as technology expands the ability to act.

Authority comes from the organization.

Authority Control evaluates proposed results against the authority the organization has established.

Browse the research: evidence, papers, and worked examples →
The convergence

Cybersecurity, governance, and AI converge where actions create organizational consequences.

Cybersecurity has spent decades strengthening control over reach: who or what can access a system. Governance defines who may decide, approve, delegate, and bind the organization. AI and automation increasingly turn access and delegated capability directly into action.

At that point, the organization still has to answer whether the result is within the authority it granted.

The problem predates AI. More capable models and agents make it more urgent by increasing the work software can carry out on the organization’s behalf.

What makes the category distinct

Tailored control over the results people, systems, and vendors may create.

The organization defines which results its people, systems, agents, and connected vendors may create. Applicable limits and conditions guide each determination. Technology and operating conditions can change while the organization retains control over the limits it has established.

Authority Control connects consequential results to the organizational authority that governs them before they take effect.
Two readings

Security and governance use the authority determination differently.

Security

Limit what valid, uncertain, compromised, automated, or third-party access may commit.

The security reading →
Governance

Carry organizational decision rights into action and preserve the resulting authority record.

Keep authority connected to the result.

The governance reading →
Current stage

Building a security-first prototype and preparing bounded design-partner engagements.

Invariance is developing a security-first Authority Control prototype and preparing bounded design-partner engagements. Current work includes scenario-based validation, integration testing, a structured evidence program, and third-party and software-supply-chain scenarios.

Engagement

Begin with one important workflow and one bounded authority question.

Begin with one important workflow or connected relationship, an accountable owner, and a defined authority question.

What the work includes
  • Scenario-based validation
  • Integration testing
  • Structured evidence development
  • Organization-specific validation