INVARIANCE | Arc
MenuClose
Authority Mapping

Where do established authority and actual capability diverge?

Authority Mapping assesses one consequential workflow by reviewing the authority the organization has established and how the workflow operates in practice. The result identifies questions for review before any enforcement decision.

The problem

Authority is defined in one set of places and enforced in many others.

Organizations define who may act and within what limits. Those rules live in policies, approval matrices, delegation letters, and signing authorities, while the controls that enforce them are spread across systems and workflows. Over time, the two can drift apart.

Review governing sources and how the selected workflow operates in practice. Identify differences that deserve organizational review.

Where authority is defined today
  • Policies
  • Approval matrices
  • Delegation letters
  • Signature authority schedules
Authority Mapping shows where the governing rules and the controls enforcing them no longer line up.
What gets compared

Compare established authority with operational practice for one workflow.

The assessment uses sources the organization already holds.

Intended authority

What the organization has authorized

Delegation of authority, signing schedules, approval matrices, risk limits, policy conditions, and the review requirements attached to each.

Technical capability

How the workflow operates in practice

Relevant roles, access, workflow configuration, and connected systems.

Observed activity

What consequential results the workflow produces

The consequential results observed in the assessed workflow, including results created by people, automation, connected parties, and AI agents.

The comparison treats divergence as a condition to review. The organization decides what the condition means and what deserves attention.

A concrete example

Illustrative example: a vendor commitment.

Assessed workflow · vendor commitment

A procurement manager holds authority for budgeted purchases within a defined amount, with additional approval required above it. The assessment compares those limits with what the workflow allows.

  • Organizational policyAuthority is defined by amount, category, and budget status, with a second approver above the threshold.
  • Identity and accessThe role that reaches the commitment screen is provisioned by function; delegated amount is defined separately.
  • System configurationThe ERP accepts commitments above the delegated threshold when the required workflow steps are completed.
  • AutomationA service account and a scheduled workflow can also initiate the same commitment path.
  • Mapped conditionAuthority for this workflow is fragmented across four systems, and the enforced capability is broader than the delegated authority.

The assessment records the observed condition for organizational review.

Illustrative example. Client-defined thresholds, categories, and approval requirements would control.
How it starts

See the gap before deciding where to enforce.

The assessment does not change production behavior. Its scope and source access are agreed for the selected workflow.

Where to enforce remains a separate decision, made by the organization.
Start with one consequential workflow

Assess value where the consequence matters.

Start with one workflow where an unauthorized result could materially affect money, operations, customers, data, or mission.

Step 01

Choose one consequential workflow.

Select a financial, operational, AI, data, vendor, or critical-system activity where an out-of-authority result would matter.

Step 02

Map the authority already in place.

Identify the policies, delegations, approvals, limits, and operating conditions the organization already uses for that result.

Step 03

Observe real proposed results.

See how results compare with established authority before changing production behavior.

Step 04

Decide where enforcement adds value.

Use the observed evidence to decide whether production enforcement is warranted.

Mapping and observation build the evidence for an enforcement decision. Enforcement depends on the organization’s decision, suitable integration, and validation for the selected workflow.

Start with a workflow