INVARIANCE | Arc
MenuClose
How it works

Different systems.
A common authority question.

People, software, AI, vendors, and workflows can reach the same kind of organizational result through different technical paths. Authority Control applies the authority that governs each consequential result.

Authority across a changing enterprise

The technology can change.
Authority remains governed.

Authority Control applies the organization’s current authority to consequential results even as actors, models, applications, and vendors change.

Authority can expire, narrow, or be revised through accountable decisions. Keeping it current, and maintaining coverage of execution paths, remains part of the work.

Path / Result / Authority

Many paths. One proposed result.

Organizational authorityAuthority that applies to the resultScope · Limits · Conditions
01 / TECHNICAL PATHS
PeopleSoftwareAI systemsVendors
02 / EXISTING CONTROLS
IdentityAccessRuntimeWorkflow

Govern actors, resources and technical paths

03 / PROPOSED RESULT
What would
take effect?

Payment · Data release · System change · Obligation

04 / COMMITMENT BOUNDARYMay this result
take effect?
PermitDeferBlock

Alternative determinations

Applied where Authority Control is integrated. Enforcement depends on integration with the execution path.Verified conditions inform evaluation. A durable determination record is preserved; execution evidence remains separate.
01 / Establish

Identify the authority.

Identify the policies, delegations, approvals, and operating rules that establish authority for the selected result.

02 / Evaluate

Examine the proposed result.

Evaluate the proposed commitment against the scope, limits, and conditions that currently apply.

03 / Determine

Permit. Defer. Block.

Within authority, unresolved, or outside authority: make the determination explicit before the result takes effect.

04 / Record

Preserve the authority basis.

Create a durable record of the proposed result, applicable authority, and determination. Execution evidence remains separate.

An illustrative payment

Valid access.
A separate authority question.

An automated workflow proposes a payment. The credentials are valid. Does the proposed result fall within the organization’s established authority?

Conceptual illustration, not a live product demonstration.

Authority determination
Permit

The result is within authority.

The required authority is present for this proposed payment. On an integrated, enforcement-enabled path, it may proceed.

A durable record accompanies the determination.
Integration & coverage

Make the control
boundary explicit.

Organizations choose the consequential workflows and execution points where Authority Control is applied.

A result may be reached through more than one path. Enforcement requires those selected paths to invoke Authority Control and apply the determination. Other paths remain outside coverage.

Existing controls retain their roles.

Identity, access, detection, workflow, and runtime controls remain part of the enterprise environment.

Observation precedes selective enforcement.

Evaluate proposed results alongside current operations before the organization decides where to enable control.

Changes to organizational limits require accountable approval.

Administrative access alone does not establish authority to change organizational limits. Organizations define how those changes are approved.

Authorization and execution are separate facts.

An authority determination establishes whether a result may proceed. It does not, by itself, prove what ultimately happened.

Begin with one workflow

Start with one
consequential workflow.

Understand the result, observe the activity, and decide where selective enforcement adds value.

Explore a design partnership