INVARIANCE | Arc
MenuClose
Connected vendors

The organization decides which results a trusted connection may create.

A vendor may need access to systems, data, or operational tools. Access to the tools and authority over the results they can produce are separate grants.

Vendors can support production systems, payments, data movement, maintenance, and recovery. Authority Control evaluates the results created through those relationships against the customer’s established authority.

Scale, scope, and pace

Connected vendors expand Scope, Scale, and Pace.

More relationships connect more systems, while vendors change their own tools and operating methods. The customer still defines its authority over the results.

The pressure in the relationship
What stays stable

Scope

A relationship can touch production systems, customer data, payments, software changes, and recovery operations, and the work runs in an environment the organization does not own.

What stays stable

Evaluate the result against the authority that applies to the relationship. Control depends on integration with the relevant execution paths.

Scale

Enterprises depend on many suppliers, platforms, and service providers at once, each with its own agreement and its own access.

What stays stable

More relationships multiply the connections, not the authority behind any one of them.

Pace

Vendor tooling, subprocessors, integrations, and automation change on the vendor’s schedule rather than the organization’s.

What stays stable

A tooling or integration change does not itself change what the customer has authorized.

What the relationship permits

Define authority for the results a vendor may create.

Existing third-party controls establish whether a vendor is approved, which credentials it receives, what systems it may access, how it is monitored, and whether the connection should remain active. Authority Control adds a separate organizational question.

Which organizational results may this vendor relationship create, under what authority, and within what conditions?

What authority applies across
01

Connected relationship

02

Consequential results the relationship may create

03

Organizational limits that apply to those results

04

Current conditions relevant to the relationship

05

Review requirements for higher-consequence activity

06

Integrated workflows where Authority Control is applied

Applied to the origin

Third-party software may act through vendor credentials, internal service accounts, workloads, or update processes. Where configured, authority requirements can apply to the known relationship or integration even when the originating supplier is uncertain.

Applied to the effect

Requirements can also apply to a proposed result, such as a production deployment, payment, or external data release. The organization defines which requirements apply.

Function-level authority

Apply authority at the level the relationship requires.

The same provider may collect telemetry, perform maintenance, deploy software, change configurations, transfer data, and support recovery. Those functions can carry different levels of organizational authority.

The customer can apply different authority requirements to different consequential results within the same relationship.

Worked relationship

Illustrative: one monitoring and update platform can support several functions with different authority requirements. The selector below shows how the same relationship can be treated differently depending on the consequential result. The organization defines its actual limits and conditions.

When conditions change

In this illustration, the connection remains active while selected consequential results face tighter conditions. Continued operation depends on the incident and surrounding security controls.

If trust in a vendor changes, the organization can apply tighter conditions to selected consequential results while investigation proceeds. Post-Breach Operations

Normal operations Approved functions operate; higher-risk functions are deferred or blocked.
Telemetry and routine health checks
Permit
Software updates into staging
Permit
Production deployment
Defer
Maintenance on regulated systems
Defer
Identity and security-control changes
Block
Privileged identity creation
Block
Unapproved external data movement
Block

Apply tighter conditions to selected results where continued connection is appropriate.

Vendor product function proposed result affected environment current conditions determination
Path / Result / Authority

Evaluate the result of each vendor function.

Organizational authorityAuthority that applies to the resultScope · Limits · Conditions
01 / TECHNICAL PATHS
MaintenanceData servicesSoftware updates
02 / CONNECTED PATHS
Connected relationshipExisting controlsCurrent conditions

Relevant context informs the authority question

03 / PROPOSED RESULT
What would
take effect?

A function can propose a consequential result

04 / COMMITMENT BOUNDARYMay this result
take effect?
PermitDeferBlock

Alternative determinations

Results only. Enforcement depends on integration with the execution path.Verified conditions inform evaluation. A durable determination record is preserved; execution evidence remains separate.
Where it matters most

Narrow higher-risk vendor functions by authority.

This control is especially relevant where organizations depend on large supplier ecosystems and cannot always disconnect every external relationship without operational cost.

01

Government contractors, shared services, and mission partners

02

Financial market infrastructure, custodians, payment processors, and data services

03

Healthcare platforms, claims processors, data exchanges, and equipment vendors

04

Critical infrastructure maintenance, operational technology, and software updates

05

Defense organizations with connected mission and supplier systems

06

Large enterprises with many business units, integrations, and jurisdictions

A SolarWinds-style illustration

Govern selected downstream actions through your own authority requirements.

SolarWinds
2020 · Software supply chain
Documented fact

A trusted software build and release path distributed compromised updates to downstream customers who accepted vendor-supplied software into their environments. Detection and prevention of supplier compromise remain responsibilities of the wider security and assurance environment.

Bounded counterfactual

Within a customer environment, a customer might Permit approved monitoring, Defer production changes, require independent authority for authentication or logging changes, and Block privileged identity creation or selected external data movement, where those actions pass through integrated authority checks. When the supplier or product is under investigation, the customer can apply tighter conditions to selected connected actions where Authority Control is integrated.

Source packet pending
Review the SolarWinds case →

Supply-chain compromise detection remains with surrounding security controls. Authority Control governs the results connected activity may create inside your environment.

Scope and readings

Control and accountability for connected activity.

Scope and dependencies

What Authority Control governs, and what remains with surrounding controls.

  • Authority Control evaluates results submitted by integrated workflows; enforcement requires those workflows to apply the determination.
  • Supplier assurance and hidden-defect inspection remain with the wider control environment.
  • Technical activity outside integrated paths remains outside Authority Control coverage.
  • Compromise detection, isolation, and technical recovery remain with connected security controls.
See the canonical scope and dependencies on How it works →
Bounded design-partner engagements

Begin with one connected relationship.

Select one vendor function or software update path, map its authority requirements, and evaluate how Permit, Defer, and Block would operate within the existing environment.

Vendor starting points
  • A monitoring or update platform
  • A managed service provider connection
  • A payment processor or data provider
  • A maintenance or automation integration
Related solution

When the result concerns data.

Explore authority for consequential data use, movement, release, and deletion.

Explore Data ↗