Govern what may proceed.
One authority determination evaluates each proposed result against the organization’s requirements. Security uses that determination to understand what may proceed and where additional authority or review is required. Arc II reads the same determination as accountability →
Security controls govern reach. Authority Control governs the result.
Identity, access, and security controls retain their roles. Authority Control evaluates whether a result falls within organizational authority.
- Identity and access decisions
- Device posture and workload context
- Network reach and threat context
- Monitoring and detection signals
- Whether the proposed result is supported by organizational authority now
- Organizational limits and conditions for selected consequential results
- Permit, Defer, or Block before the result takes effect
- A durable record of every determination
Compare access controls with authority over the result.
| Posture | Zero Trust, at access | Authority Control, at the result |
|---|---|---|
| Verify explicitly | Verify identity, device, network, and workload. | Verify that the proposed result is within established authority. |
| Least privilege | Minimum access per function. | Minimum authority per function. |
| Assume breach | Contain access laterally. | Contain the result to the scope of established authority. |
| Fail closed | Access requires verification. | Results require Permit to proceed where enforcement is enabled. |
| Record | Log access events. | Create a durable authority record with every determination. |
Zero Trust and adjacent controls contribute current context. The organization defines the authority requirements. Authority Control applies them to the proposed result.
The same authority question appears across routine, vendor, incident, and agent activity.
Routine high-consequence actions
Payments, disclosures, releases, and changes evaluated under ordinary requirements during normal operations. Five industry workflows →
Connected vendors
Connected vendor activity evaluated according to the consequential result and the authority the organization has established. Connected vendors →
Uncertain trust and Post-Breach
Selected consequential results can face tighter conditions while investigation continues. Post-Breach →
Advanced agents
Agent capability can expand while organizational authority remains organization-defined and each consequential action is evaluated. Frontier Agentic Systems →
How security teams can use the determination.
Narrower authority exposure
The organization defines the authority applicable to each result.
Selective control
Where configured, higher-risk results can Defer or Block while authorized activity continues.
Recorded attempts
Permit, Defer, and Block each produce a durable authority record for review.
Recovery
Normal operating conditions can return through accountable organizational decisions.
What tighter authority changes during misuse.
As consequential activity grows, security teams need to understand both what can be reached and what may take effect. The authority determination addresses the result.
What is being committed?
The consequential result that matters
Commitments visible through their authority records
Should this proceed?
The ability to commit beyond established authority limits
Organizational authority remains distinct from technical access
Who is committing?
Authority beyond the compromised identity’s scope
Results linked to a durable determination record
What happened?
The ability to act without producing a record
A durable record of each authority determination
Containment, when access is valid.
On integrated, enforcement-enabled paths, Authority Control applies organizational authority before the result takes effect. Activity outside those paths remains outside its coverage.