Arc I · Security · Explainer
Authority Control + Zero Trust

Zero Trust secures access. Authority Control secures consequence.

Zero Trust verifies who can reach the system. Authority Control verifies what organizational authority may be exercised through it.

From access control to authority control

Two boundaries. Two different questions.

Zero Trust verifies access. Authority Control determines whether the resulting action carries organizational authority.

01What Zero Trust solved

Zero Trust replaced trust based on network location with continuous verification of identity, device, session, and resource access.

It answers Who can get in, from what device, and under what conditions?
02What remains open

Access can be valid while the resulting action is still outside the authority granted.

Authority Control answers Does this action carry organizational authority?

Authority Control operates at that boundary.

A governed feedback loop

Authority improves through use.

The organization reviews how authority is exercised and refines the governing scope. Authority Control does not change authority on its own.

01 Determine and record

Each governed commitment produces an authority decision and a durable record.

02 Review

The records show where scope is too broad, where thresholds should change, and where additional commitment classes need explicit governance.

03 Refine

The organization updates its authority scope, and Authority Control applies that refined scope to future commitments.

Access controls show who should be able to reach a system. Authority Control shows how organizational authority is actually exercised.

Zero Trust + Authority Control

Access governed. Commitment controlled. Together they limit consequence.

AI increases the urgency, but the boundary exists anywhere access can create an organizational commitment. Three views of the same stack. Select a view.

Zero Trust: the current state Identity Device Network Workload Data ACCESS BOUNDARY COMMITMENT BOUNDARY (absent) BINDING CONSEQUENCE unverified authority Access is governed Bind is ungoverned
Zero Trust alone: access is verified, while the resulting commitment remains ungoverned.

Access is governed. Commitment is not. Verified identities can create obligations without authority verification.

Identity
Verifies who is requesting access. Covers authentication, multi-factor verification, and identity federation across systems.
Device
Verifies the endpoint meets compliance standards. Checks patch level, encryption status, and device health before granting access.
Network
Verifies the network path is authorized. Enforces segmentation, encrypted tunnels, and path-level access policies.
Workload
Verifies the application is approved and unmodified. Validates container integrity, runtime behavior, and workload authorization.
Data
Verifies data access is classified and permitted. Enforces encryption, data loss prevention, and access-level logging.
Authority Control ACCESS BOUNDARY (not governed here) AC also governs here Authority Check Authority verified Identity attributable Record created GOVERNED · ATTRIBUTED · TRACED Access governed elsewhere Bind is governed
With Authority Control: the authority decision operates after access is permitted and before the consequence takes effect.

Authority Control introduces structural control over organizational commitment. It does not replace access control. It governs what access can commit. Every governed action passes through the Authority Check: authority verified, identity attributable, record created.

Authority verified
Confirms that the actor holds organizational authority for this specific commitment. Not just valid credentials or system access, but authorization for the type, scope, and magnitude of the proposed action.
Identity attributable
Links the commitment to an attributable identity. For automated systems, the documented authorization path traces the action back to the human principal who authorized it. Every commitment has an accountable owner.
Record created
Creates a durable record of the decision and its scope when the action takes effect. It captures who authorized the action, what authority applied, what information was available, and what scope was permitted.
What Authority Control does, and does not, claim

Authority Control constrains unauthorized consequence outside defined authority scope. It also surfaces unusual commitment patterns within scope through decision records and cumulative telemetry where configured.

What Authority Control does not claim to do is detect every possible misuse of legitimate authority. No system can block legitimate behavior that is indistinguishable from normal use, and Authority Control does not pretend otherwise.

The architecture provides two mechanisms that address the residual risk inside authorized scope. First, scope can be narrowed iteratively based on observed behavior, using the decision records as evidence of where authority is too broad. Second, within-scope patterns can be signaled to the access layer for further scrutiny.

Combined: Zero Trust + Authority Control Identity Device Network Workload Data ACCESS BOUNDARY AC: binding access decisions provision · elevate · connect · trust Verified access, pending authority Authority Check Authority verified Identity attributable Record created GOVERNED · ATTRIBUTED · TRACED Access governed. Commitment controlled. Binding consequence bounded. Zero Trust governs reach Authority Check governs bind Combined governs consequence
Combined: Zero Trust governs reach; Authority Control governs the consequence that reach can create.

Authority Control governs the commitment boundary wherever organizational consequence is created, including inside the access layer: provisioning a new identity, elevating privileges, approving an API integration, or modifying a trust relationship. The access management system verifies permission to perform the operation. Authority Control verifies authority to create the resulting organizational obligation.

Constrain · Inform · Enforce

Authority Control performs three operational roles alongside Zero Trust. Authority Observation Mode and Enforcement-Active Mode are set per commitment class and can operate alongside one another.

  • Constrain: define the bounded authority scope for each commitment class, including identity, purpose, destination, scale, conditions, and configured cumulative limits.
  • Inform: return authority findings, unusual commitment patterns, and decision records to connected controls and responsible operators.
  • Enforce: apply Permit, Defer, or Block at the commitment boundary before the resulting consequence takes effect.

Every governed determination produces a durable authority record. In Authority Observation Mode, AC computes and records the determination without controlling the live transition, helping the organization map authority exposure, design Defer paths, and review proposed narrowing. In Enforcement-Active Mode, AC applies Permit, Defer, or Block at the boundary. Observation can continue for other commitment classes while selective enforcement is active.

The gap appears across domains. The structural signature is the same. See the evidence across domains →

Deployed at the consumer edge

The customer defines the scope. Authority Control enforces it.

Authority Control is deployed by the organization that defines scope, at the consumer edge of every platform it uses. No platform vendor cooperation is required. That is what makes deployment possible now.

Zero Trust: access verified
Access boundary
Authority Control: consequence governed
Commitment boundary

Authority Control does not extend Zero Trust. It operates at a different boundary. Each layer governs independently. Together, they govern both reach and consequence.

Zero Trust established that implicit access is an unacceptable risk. Authority Control establishes that implicit authority is the same category of risk.
Access is verified. Consequence is governed. Both boundaries closed.

Design partners

Two boundaries, independently governed.

Authority Control does not prevent credential compromise. It prevents compromised credentials from creating unauthorized consequence.