May this actor commit the organization to this spend, trade, vendor, or obligation?
Financial commitments are evaluated against authorized scope and prior determinations before they take effect. One payment or trade may be permitted on its own while the sequence exceeds the authority granted.
Each payment may clear on its own. The sequence may exceed the authority granted.
A permitted payment path initiates a vendor transaction.
Each payment clears workflow and account checks on its own.
The Authority Check evaluates amount, counterparty, purpose, scope, and cumulative exposure where configured.
A vendor limit applies across the sequence, not only to each payment.
A procurement team may commit up to $100,000 to one vendor within 30 days. Additional authority is required when proposed exposure reaches $90,000.
What changes across the sequence: The fourth payment raises proposed exposure above the $90,000 review threshold, so AC defers it for additional authority. The fifth would exceed the $100,000 authorized limit and is blocked. Each payment may look ordinary when viewed alone.
Illustrative configuration only. Client-defined limits, periods, and escalation rules would control.Without the Authority Check, the organization may discover cumulative exposure only after the sequence has already committed funds. With it, each proposed payment is evaluated against authority already exercised during the configured period, and the determination is recorded before the next obligation takes effect.
Warnings were visible. The next trade was not constrained.
Traders at JPMorgan's Chief Investment Office grew a portfolio from $51 billion to $157 billion in notional exposure over one quarter. Internal risk limits were breached more than 330 times. Each breach generated a warning. None prevented the next trade. The trading system permitted financial obligations the organization never authorized at that scale.
Every access control passed. Trader identity was authenticated, platform access was role-authorized, risk monitoring and transaction logging were operational, and no anomalous access behavior was detected. The failure sat at the point where new exposure became an organizational obligation.
Risk limits become structural constraints on the next commitment.
As limits are approached, the range of permitted actions narrows. Financial authority is evaluated per action and across the sequence.
- Cumulative position limits apply as structural constraints, not advisories.
- Splitting a commitment across requests does not evade cumulative evaluation.
- What actions are allowed narrows as risk limits are approached.
- Model changes require independent authorization before the next trade.
- Durable records link each trade, payment, and obligation to verified authority.
Every evaluation returns Permit, Defer, or Block, and every determination produces a record.
Authority Control evaluates and records the authority determination before the obligation takes effect. Where a consequence is attempted beyond authority, the organization holds a contemporaneous record of its determination, which supports escalation and prompt response.
Where cumulative limits are configured, exposure across related commitments is part of the authority question.
The organization defines limits, counterparties, and escalation paths. The boundary evaluates the next commitment against them.