Arc I · Security

Constrain consequence when access is valid.

Security asks what valid or stolen access can be used to do. Within governed workflows, Authority Control limits that access to the actions and consequences the organization actually authorized, not everything the connected systems can technically perform.

Convergence

Different vectors. One structural gap.

Insider misuse, network compromise, supply-chain tampering, telecom surveillance, critical-infrastructure pre-positioning, and agent misuse differ in vector and converge on the same pattern: access is verified, authority is not. The documented cases live on the Evidence page. Each commitment surface shows the boundary for its domain: Data, AI agents, Software and infrastructure, and Finance and procurement.

Posture mapping

Every principle Zero Trust applies to access, Authority Control applies to commitment.

PostureZero Trust (access)Authority Control (commitment)
Never trustNo access without verificationNo commitment without verified authority
Always verifyVerify identity, device, network, workload, dataVerify authority, scope, timing, cumulative exposure where applicable, and documented authorization path
Assume breachContain access laterallyContain commitment to the scope of verified authority
Least privilegeMinimum access per functionMinimum authority per function
Fail closedDeny access by defaultDeny commitment by default
RecordLog access eventsCreate a durable record of the decision and its scope with every commitment

In each documented case, security controls verified identity and access and operated as designed. The failure occurred because no system evaluated whether the actor held authority to create the resulting organizational obligation.

Post-Breach Containment

Security restricts access as evidence develops. Authority Control limits high-consequence financial, data, and automated actions across governed workflows while the investigation continues. Permit preserves lower-risk operations, Defer routes legitimate exceptions for additional accountable authority, and Block closes paths the institution will not accept under the current posture.

Explore Post-Breach Containment →

Threat vectors

Where valid access still creates organizational consequence.

Zero Trust verifies access. The commitment boundary answers a different question: does this action carry organizational authority? Select a threat vector to see where authentication and authority separate.

+ AI & Agent Misuse + Supply Chain + Insider Threat + Network Compromise + Critical Infrastructure + Telecom & Surveillance COMMITMENT BOUNDARY NO STRUCTURAL GATE Binding consequence Irreversible organizational or physical obligation

Select a threat vector

AI & Agent Misuse
Capability-authority conflation, autonomous commitment
AI agents act anywhere they have system access. Access is treated as authority: if an agent can reach it, it can commit on behalf of the organization. Authority Control addresses this gap. Consequence is limited to the authority explicitly assigned, not the full capability of systems the agent can access.
Palisade Research GTG-1002, 2025
A coding agent scoped for software development was redirected into an autonomous cyber attack agent, executing 80-90% of offensive operations independently across roughly 30 targets. The agent's deployment-time scope had no structural relationship to its execution-time behavior.
Access capability and commitment authority were treated as equivalent. The agent's commitment scope expanded with no structural constraint.
Agent capability expands continuously. Authority Control constrains organizational consequence to what was explicitly authorized.
  Back to convergence
Supply Chain
Trust propagation, commitment multiplication
Connecting a service or installing software delegates the ability to act on the organization's behalf. The reviewed version may differ from the one running months later. Authority Control brings discipline to consequential changes over time, limiting blast radius to what the system is authorized to commit, not everything it can access.
SolarWinds SUNBURST, 2020
Attackers inserted code after human review but before compilation. 18,000+ organizations received compromised updates. The reviewed source was not the compiled binary.
Authority was delegated to "whatever runs as Orion" rather than to specific authorized behaviors. The software changed. The authority persisted.
MCP Rug Pull Attacks, 2024-25
A tool approved at installation can later change what it does. Researchers showed a benign tool could be modified to exfiltrate API keys post-installation. The original authority remained while the behavior changed.
The commitment boundary was evaluated once, at installation. The actual commitment changed continuously with no re-verification.
Software changes. Integrations evolve. The organizational consequence each can produce remains bounded by the authority granted to that integration identity.
  Back to convergence
Insider Threat
Authorized access, unconstrained consequence
An insider with valid access can create consequences beyond their authority. Detection alerts after the fact. Authority Control governs consequential actions, limiting blast radius to what that person is authorized to commit, not everything their credentials can reach.
UBS / Kweku Adoboli, 2011
A trader created fictitious hedges to conceal $2.3 billion in unauthorized trading losses. His system access was legitimate. His authority was not.
No structural control governed the positions he could create. Access and commitment authority were treated as equivalent.
Cisco / Sudhish Ramesh, 2018
A former employee retained cloud access and deleted 456 virtual machines, taking WebEx Teams offline for weeks. His credentials were valid. His authority to execute destructive changes was not.
The commitment boundary had no structural enforcement of authority scope for infrastructure changes.
Authorized access creates reach. Authority Control separates what credentials can touch from the organizational consequence they can produce.
  Back to convergence
Network Compromise
Lateral movement to consequential action
Attackers can move past defenses and detection. When access is used to create a consequential action, Authority Control constrains what that access can produce, limiting blast radius to what the compromised identity is authorized to commit and shielding the rest of the system.
Volt Typhoon, 2023-ongoing
A Chinese state-sponsored group maintained access inside U.S. critical infrastructure for months using built-in administrative tools. They could reach operational systems. Nothing separated that access from the ability to issue consequential operational commands.
The commitment boundary had no structural gate between network access and organizational consequence.
Bangladesh Bank, 2016
$81 million transferred through authenticated SWIFT credentials. Adversaries gained network access, reached the SWIFT terminal, and issued transfers the system executed as legitimate.
The commitment boundary had no authority verification for the specific transfer class and magnitude.
Lateral movement extends an attacker's reach. Authority Control limits the consequence that reach can create, regardless of how many systems the attacker can access.
  Back to convergence
Critical Infrastructure
Digital command, physical consequence
In operational systems, digital commands become physical actions. Few govern authority at points of physical consequence. Authority Control applies there, limiting blast radius to what the commanding identity is authorized to do and mitigating cascade effects.
Oldsmar Water Treatment, 2021
An attacker remotely accessed the SCADA system and changed sodium hydroxide levels from 100 to 11,100 ppm. An operator reversed it in real time. The command was structurally identical to an authorized command.
Remote access was equivalent to authority to alter chemical dosing at any level. The commitment boundary had no structural gate.
Ukraine Power Grid Attack, 2015
Attackers issued commands that opened circuit breakers, cutting electricity to 230,000 people for six hours. The commands were structurally identical to authorized operator commands.
Authenticated access and operational authority were treated as equivalent. The commitment boundary had no gate distinguishing authorized operators from adversaries.
Where digital commands create physical obligation, Authority Control constrains what any commanding identity can produce within the limits of delegated authority.
  Back to convergence
Telecom & Surveillance
Protocol authority, mass commitment
Telecom protocols often treat authenticated messages as authorized. At the commitment boundary, authentication and authority remain conflated. Authority Control separates the two, limiting blast radius to the sanctioned scope of the requesting identity.
Salt Typhoon, 2024-25
A Chinese state-sponsored group compromised at least nine major U.S. telecom providers over one to two years, accessing lawful intercept systems and the communications data of over a million users. They intercepted audio recordings from senior political figures including presidential candidates, and obtained sealed court orders identifying active surveillance targets. The intercept systems verified network credentials. They did not structurally verify that the requesting identity held sanctioned authority for those specific interceptions.
The intercept boundary authenticated the connection. It did not verify authority to surveil.
The blast radius of telecom compromise is bounded by the sanctioned scope of the requesting identity.
With Authority Control, out-of-scope interception attempts become visible. The compromise may still occur. What changes is the scope of consequence the compromised identity can create.
  Back to convergence
Design partners

Containment, when access is valid.

Within governed surfaces, authorized or compromised access is structurally constrained to its authorized scope, and every attempt is recorded.