INVARIANCE | Arc
MenuClose
How it fits

Where Authority Control fits with the controls you already run.

Existing controls govern identity, access, data, workflow, runtime conditions, and response. Authority Control evaluates whether the result is within the authority the organization has established.

Composition

How Authority Control fits

Existing controls govern identity, access, data, workflow, runtime conditions, and response. Authority Control applies the organization’s established authority to consequential results before they take effect.

Existing controls continue to provide identity, access, runtime, workflow, and security context. Authority Control applies the organization’s established authority to the result, and connected systems can use the determination where integrated.

Path / Result / Authority

Many paths. One proposed result.

Organizational authorityAuthority that applies to the resultScope · Limits · Conditions
01 / TECHNICAL PATHS
PeopleSoftwareAI systemsVendors
02 / EXISTING CONTROLS
IdentityAccessRuntimeWorkflow

Govern actors, resources and technical paths

03 / PROPOSED RESULT
What would
take effect?

Payment · Data release · System change · Obligation

04 / COMMITMENT BOUNDARYMay this result
take effect?
PermitDeferBlock

Alternative determinations

Applied where Authority Control is integrated. Enforcement depends on integration with the execution path.Verified conditions inform evaluation. A durable determination record is preserved; execution evidence remains separate.
Durable authority recordEvery determination leaves a durable record.
TIMEPROPOSED RESULTDETERMINATIONRECORD
14:02:15Zpayment release to a counterparty added this morningPermitAC-4471-04

Existing controls govern the actors, systems, access, and workflows along the way. Authority Control governs whether the result may bind. Permit means the result may proceed toward binding, and execution is performed by the connected system.

Pillar and capability labels identify components within the Zero Trust maturity model. Zero Trust itself is the architecture they belong to.

Existing control
Authority Control adds

Zero Trust

Architecture

Verifies requests to protected resources and applies access policy.

Authority Control adds

Evaluates whether the proposed result is supported by organizational authority before it takes effect.

Zero Trust and Authority Control →

Identity and access management

Identity pillar

Establishes who or what is acting and what resources that identity may access.

Authority Control adds

Evaluates whether the result is within the authority granted to that actor.

Identity and authority →

Network segmentation

Networks pillar

Limits which systems can communicate and how far a compromise can spread.

Authority Control adds

Within a permitted segment, constrains selected high-consequence actions by authority.

Reach and authority, side by side →

Data governance and loss prevention

Data pillar

Controls the permitted use, movement, and release of information.

Authority Control adds

Evaluates a proposed use, transfer, or release against the authority and limits the organization has defined for that action.

Data at the boundary →

Change management and CI/CD

Applications and Workloads pillar

Approves and delivers system changes through controlled processes.

Authority Control adds

Evaluates whether a change may be configured, deployed, or promoted into production before it takes effect.

A deployment, walked through →

Workflow and approval systems

Business process

Route actions through configured steps, approvals, and exceptions.

Authority Control adds

Evaluates the proposed result against the authority and conditions that apply at that moment. When authority changes, the same workflow can return a different answer.

Same workflow, changed authority →

Third-party risk management

Adjacent program

Assesses vendors before and during the relationship.

Authority Control adds

Evaluates results created through connected vendor workflows.

Connected vendors →

Incident response

Adjacent program

Contains incidents, supports recovery, and restores operations.

Authority Control adds

Applies narrower organizational authority to selected results where configured.

Post-breach authority control →

Security orchestration and automated response

Cross-cutting capability

Triages alerts and executes response playbooks automatically or with operator approval.

Authority Control adds

Evaluates whether an automated action may disable, revoke, isolate, or halt before it takes effect.

Automated narrowing, observed first →

Every proposed result receives a Permit, Defer, or Block determination and a durable authority record.

Adjacent mechanisms

A different question about the same enterprise activity.

Authority Control works alongside mechanisms enterprises already use. Policy engines, limits, identity systems, review workflows, and audit platforms continue to perform their existing roles. Authority Control adds a separate organization-level determination about the consequential result.

Policy engines

Policy engines can implement approved organizational rules within existing systems.

Authority Control evaluates the consequential result against the authority the organization has established.

Rate and velocity limits

Organizations may establish limits for consequential activity.

Where configured, Authority Control applies those organizational limits before consequential results take effect.

Entitlement discovery

Authority Mapping examines how stated authority relates to operational practice.

Entitlement discovery inventories permissions. Authority Mapping helps identify where organizational authority and operational practice may differ.

Step-up authentication

Defer leaves the authority question unresolved.

The organization’s existing process supplies the authority, evidence, or review needed to resolve the question.

Append-only audit logs

The authority record accompanies every determination.

The record preserves the proposed result and the determination for review.

Existing enterprise mechanisms can support the process
Policy engines Limits and counters Identity and entitlements Review workflows Audit systems Existing security controls

Policy engines, limit controls, approval workflows, and audit systems already perform important functions. Authority Control adds an organization-level authority determination before consequential results take effect.

Related solution

When the result concerns data.

Explore authority for consequential data use, movement, release, and deletion.

Explore Data ↗