INVARIANCE | Arc
MenuClose
Industries / Government & defense

Keep mission commitments within delegated authority.

Software releases and operational changes across agencies, contractors, and connected systems.

Discuss a workflow ↗
Unbranded civic campus with limestone colonnades and glass architecture
Industries

Government and defense organizations delegate authority across missions, roles, and operating environments. This illustrative workflow follows a proposed mission-software release.

Representative workflow

Apply delegated authority to mission software releases and operational changes.

The workflow is illustrative. Each organization defines its own authority, evidence requirements, exceptions, and operating conditions.

Defense & Mission Operations

Mission software capability release to an operational environment

A mission-software release brings together development, testing, readiness review, and approval for a defined operational environment.

Authority Control point. After mission context, test evidence, security evidence, user acceptance, and operational-readiness information have been assembled, but before deployment into the selected operational environment.

Normal operations Approved releases proceed within release authority. Mission-critical and sensitive-interface changes are deferred.
Proposed action class
Normal operations
When trust degrades
Restore deliberately
Approved capability release to an authorized environment
PermitWithin release authority
PermitWithin narrowed conditions
PermitLimits restored first
Routine update within approved mission and interface conditions
PermitWithin approved conditions
PermitMonitoring and lower-risk updates
PermitLimits restored first
Release affecting mission-critical functions or external interfaces
DeferPending evidence or independent participation
BlockClosed until evidence returns
DeferRetained until evidence returns
Nonessential capability change
PermitWithin release windows
DeferHeld while attribution is incomplete
PermitRelease windows reopened by approval
Privilege, identity, logging, external-interface, or protected mission-function change
BlockUnless separately authorized
BlockUnless separately submitted and reevaluated
BlockSeparate authorization still required
Deployment to an unauthorized environment
BlockOutside authorized environment
Block
Block

Workflow basisDoDI 5000.87, DoD Enterprise DevSecOps Fundamentals Version 2.5, Continuous Authorization to Operate Evaluation Criteria for the DevSecOps use case, and the DevSecOps Continuous Authorization Implementation Guide.

Sources and evidence →

Illustrative workflow adapted from public regulatory, standards, acquisition, and operational sources. It identifies a recognizable operating sequence and a possible Authority Control point; compliance obligations and sector requirements are determined separately.

Exceptions follow the organization’s review process. Results may be reevaluated after additional authority, evidence, or review resolves a Defer. The determinations remain Permit, Defer, and Block.