INVARIANCE | Arc
MenuClose
Executive brief · 5 minutes

Authority Control: the executive brief.

A person, system, vendor, or AI agent may have valid access while lacking authority for the result it proposes. Authority Control evaluates that result against the organization’s established authority before it takes effect.

The problem

Valid access can still create a result the organization never authorized.

Existing controls can enforce approvals and limits within their configured scope. A gap remains when their decisions do not resolve authority for the resulting commitment as a whole, especially across systems or related actions.

The commitment boundary

Where a proposed result becomes organizational consequence.

A payment settles. Data leaves. A configuration changes. A contract binds. Each is a point where activity becomes consequence and where the organization’s authority can be evaluated before the result takes effect.

Authority governs a different question from access

Access controls govern reach. Authority Control governs the result.

Identity establishes who or what is acting. Access establishes what it can reach. Runtime controls evaluate whether systems are operating as expected. Authority asks whether the identified organizational result may take effect. Organizational authority remains defined by the organization as actors, capability, access, and paths expand.

What it returns

Permit, Defer, or Block, with a durable record.

Permit

The proposed result is within established authority and may proceed. Permit does not prove execution.

Defer

The authority question remains unresolved. Additional authority, evidence, or review is required.

Block

The result is outside established authority. It does not proceed on an integrated, enforcement-enabled path.

Each determination creates a durable record of the proposed result, the authority applied, and the determination.

Where it applies

Payments. Data releases. System changes. Obligations.

Supplier payments, data exports, production deployments, approval-limit changes, vendor actions, and AI-agent tasks can all create consequential results that require organizational authority.

Fit with existing controls

Complementary, and bounded.

Existing identity, Zero Trust, workflow, transaction, data, safety, and monitoring systems remain necessary. Authority Control is complementary to them and relies on them. Coverage extends to the consequential results the organization places under evaluation, and no further. How Authority Control works →