INVARIANCE | Arc
MenuClose
Authority Control + Zero Trust

Zero Trust governs access. Authority Control governs whether the result may take effect.

Zero Trust governs access to resources. Authority Control governs whether the resulting consequence may take effect. The two controls operate at different points in the same enterprise activity.

Two boundaries

Access and organizational authority answer different questions.

Both questions matter to the same enterprise activity.

01Access boundary

Zero Trust requires explicit access decisions based on identity, resources, and relevant conditions rather than implicit trust in network location.

It settles Who or what may reach the resource under current conditions?
02Commitment boundary

Organizational authority applies to the result the activity would create. Authority Control evaluates that result against the authority the organization has established.

It settles May this result take effect for the organization?

Authority Control operates at that boundary.

Path / Result / Authority

Access and commitment answer different questions.

Organizational authorityAuthority that applies to the resultScope · Limits · Conditions
01 / TECHNICAL PATHS
PersonServiceAI agent
02 / ACCESS BOUNDARY
Who or what?Which resource?What access?

May it reach the resource?

03 / PROPOSED RESULT
What would
take effect?

Valid access does not settle organizational authority

04 / COMMITMENT BOUNDARYMay this result
take effect?
PermitDeferBlock

Alternative determinations

Applied where Authority Control is integrated. Enforcement depends on integration with the execution path.Verified conditions inform evaluation. A durable determination record is preserved; execution evidence remains separate.
Identity
Establishes who or what is requesting access through authentication and identity assurance.
Device
Assesses endpoint posture, such as patch level, encryption, and device health, where configured.
Network
Restricts network communication through segmentation and access policies.
Workload
Assesses application and workload context, integrity, and behavior using the controls deployed.
Data
Applies data-access and protection requirements, including classification, encryption, and loss prevention where configured.
Context in, evidence out

Use security context in the authority determination.

Security controls provide relevant context. Authority Control evaluates the result against organizational authority.

Security controls

Relevant identity, device, session, workload, resource, and security context.

Authority Control

Evaluates whether the proposed consequential result is within the authority the organization has established.

Permit · Defer · Block

Each determination leaves a durable authority record.

Security and operations

Authority determinations can provide additional evidence for investigation, access review, and response where integrated.

Security context into Authority Control

Security controls can provide relevant context for an Authority Control determination while retaining responsibility for access and technical trust decisions.

Authority evidence into security operations

Each determination leaves a durable record that can support later review where integrated. Access decisions remain with the systems that own them.

Narrower access reduces technical reach. Authority Control evaluates which results may take effect.

Deployment relationship

Authority Control evaluates the result within the scope the organization defines.

Deployment depends on the selected workflow and the integration point. Identity, Zero Trust, workflow, data, and security systems can provide context or implementation mechanisms. Organizational authority comes from the organization, and Authority Control applies it at the commitment boundary.

Scope and residual coverage

Authority Control applies defined authority scope at consequential results. Compromise and misuse assessment remain with surrounding security controls.

A determination states whether the proposed result is within authority, outside it, or unresolved. It does not establish the actor’s intent.

Access verification and organizational authority remain separate questions. Both can apply before a consequential result takes effect.

Design partners

Coverage and integration define where control applies.

A compromised credential may retain technical reach. On an integrated, enforcement-enabled path, Authority Control constrains the resulting commitment by the authority that applies.