Where Authority Control fits with the controls you already run.
Existing controls govern identity, access, data, workflow, runtime conditions, and response. Authority Control evaluates whether the result is within the authority the organization has established.
How Authority Control fits
Existing controls govern identity, access, data, workflow, runtime conditions, and response. Authority Control applies the organization’s established authority to consequential results before they take effect.
Existing controls continue to provide identity, access, runtime, workflow, and security context. Authority Control applies the organization’s established authority to the result, and connected systems can use the determination where integrated.
Many paths. One proposed result.
Govern actors, resources and technical paths
take effect?
Payment · Data release · System change · Obligation
take effect?
Alternative determinations
Existing controls govern the actors, systems, access, and workflows along the way. Authority Control governs whether the result may bind. Permit means the result may proceed toward binding, and execution is performed by the connected system.
Pillar and capability labels identify components within the Zero Trust maturity model. Zero Trust itself is the architecture they belong to.
Zero Trust
ArchitectureVerifies requests to protected resources and applies access policy.
Evaluates whether the proposed result is supported by organizational authority before it takes effect.
Zero Trust and Authority Control →Identity and access management
Identity pillarEstablishes who or what is acting and what resources that identity may access.
Evaluates whether the result is within the authority granted to that actor.
Identity and authority →Network segmentation
Networks pillarLimits which systems can communicate and how far a compromise can spread.
Within a permitted segment, constrains selected high-consequence actions by authority.
Reach and authority, side by side →Data governance and loss prevention
Data pillarControls the permitted use, movement, and release of information.
Evaluates a proposed use, transfer, or release against the authority and limits the organization has defined for that action.
Data at the boundary →Change management and CI/CD
Applications and Workloads pillarApproves and delivers system changes through controlled processes.
Evaluates whether a change may be configured, deployed, or promoted into production before it takes effect.
A deployment, walked through →Workflow and approval systems
Business processRoute actions through configured steps, approvals, and exceptions.
Evaluates the proposed result against the authority and conditions that apply at that moment. When authority changes, the same workflow can return a different answer.
Same workflow, changed authority →Third-party risk management
Adjacent programAssesses vendors before and during the relationship.
Evaluates results created through connected vendor workflows.
Connected vendors →Incident response
Adjacent programContains incidents, supports recovery, and restores operations.
Applies narrower organizational authority to selected results where configured.
Post-breach authority control →Security orchestration and automated response
Cross-cutting capabilityTriages alerts and executes response playbooks automatically or with operator approval.
Evaluates whether an automated action may disable, revoke, isolate, or halt before it takes effect.
Automated narrowing, observed first →Every proposed result receives a Permit, Defer, or Block determination and a durable authority record.
A different question about the same enterprise activity.
Authority Control works alongside mechanisms enterprises already use. Policy engines, limits, identity systems, review workflows, and audit platforms continue to perform their existing roles. Authority Control adds a separate organization-level determination about the consequential result.
Policy engines
Policy engines can implement approved organizational rules within existing systems.
Authority Control evaluates the consequential result against the authority the organization has established.
Rate and velocity limits
Organizations may establish limits for consequential activity.
Where configured, Authority Control applies those organizational limits before consequential results take effect.
Entitlement discovery
Authority Mapping examines how stated authority relates to operational practice.
Entitlement discovery inventories permissions. Authority Mapping helps identify where organizational authority and operational practice may differ.
Step-up authentication
Defer leaves the authority question unresolved.
The organization’s existing process supplies the authority, evidence, or review needed to resolve the question.
Append-only audit logs
The authority record accompanies every determination.
The record preserves the proposed result and the determination for review.
Policy engines, limit controls, approval workflows, and audit systems already perform important functions. Authority Control adds an organization-level authority determination before consequential results take effect.
Explore the evaluation and its coverage.
When the result concerns data.
Explore authority for consequential data use, movement, release, and deletion.
Explore Data ↗