INVARIANCE | Arc
MenuClose
Arc I · Security

Govern what may proceed.

One authority determination evaluates each proposed result against the organization’s requirements. Security uses that determination to understand what may proceed and where additional authority or review is required. Arc II reads the same determination as accountability →

Composition

Security controls govern reach. Authority Control governs the result.

Identity, access, and security controls retain their roles. Authority Control evaluates whether a result falls within organizational authority.

Security controls contribute
  • Identity and access decisions
  • Device posture and workload context
  • Network reach and threat context
  • Monitoring and detection signals
Authority Control adds
  • Whether the proposed result is supported by organizational authority now
  • Organizational limits and conditions for selected consequential results
  • Permit, Defer, or Block before the result takes effect
  • A durable record of every determination

Compare access controls with authority over the result.

PostureZero Trust, at accessAuthority Control, at the result
Verify explicitlyVerify identity, device, network, and workload.Verify that the proposed result is within established authority.
Least privilegeMinimum access per function.Minimum authority per function.
Assume breachContain access laterally.Contain the result to the scope of established authority.
Fail closedAccess requires verification.Results require Permit to proceed where enforcement is enabled.
RecordLog access events.Create a durable authority record with every determination.

Zero Trust and adjacent controls contribute current context. The organization defines the authority requirements. Authority Control applies them to the proposed result.

Operating situations

The same authority question appears across routine, vendor, incident, and agent activity.

Routine high-consequence actions

Payments, disclosures, releases, and changes evaluated under ordinary requirements during normal operations. Five industry workflows →

Connected vendors

Connected vendor activity evaluated according to the consequential result and the authority the organization has established. Connected vendors →

Uncertain trust and Post-Breach

Selected consequential results can face tighter conditions while investigation continues. Post-Breach →

Advanced agents

Agent capability can expand while organizational authority remains organization-defined and each consequential action is evaluated. Frontier Agentic Systems →

Outcomes

How security teams can use the determination.

Narrower authority exposure

The organization defines the authority applicable to each result.

Selective control

Where configured, higher-risk results can Defer or Block while authorized activity continues.

Recorded attempts

Permit, Defer, and Block each produce a durable authority record for review.

Recovery

Normal operating conditions can return through accountable organizational decisions.

Two effects, one enforcement point

What tighter authority changes during misuse.

As consequential activity grows, security teams need to understand both what can be reached and what may take effect. The authority determination addresses the result.

Question The adversary loses The organization gains

What is being committed?

The adversary loses

The consequential result that matters

The organization gains

Commitments visible through their authority records

Should this proceed?

The adversary loses

The ability to commit beyond established authority limits

The organization gains

Organizational authority remains distinct from technical access

Who is committing?

The adversary loses

Authority beyond the compromised identity’s scope

The organization gains

Results linked to a durable determination record

What happened?

The adversary loses

The ability to act without producing a record

The organization gains

A durable record of each authority determination

Design partners

Containment, when access is valid.

On integrated, enforcement-enabled paths, Authority Control applies organizational authority before the result takes effect. Activity outside those paths remains outside its coverage.

Discuss one consequential workflow