A valid identity does not settle authority for the result.
Identity establishes who or what is acting. Access governs what it can reach. Authority Control evaluates whether the result is within current organizational authority.
The credential can be valid while the result exceeds authority.
A human, service account, workload, device, integration, or agent may be authenticated and permitted to reach a system. That still leaves a different question: what organizational results may this actor create through that access?
Proofing, authentication, federation, claims, credentials, and accountable actor context.
Applications, APIs, data, workflows, systems, and technical operations.
Payments, deployments, exports, deletions, approvals, transfers, filings, and other organizational results.
Organizational authority remains distinct from identity and access.
Employees, contractors, officers, approvers, and operators.
Service accounts, integrations, workloads, devices, and automated pipelines.
Agents acting under the scope and conditions established by the organization.
Automated actors operating under authority established by the organization.
The same identity can be associated with different authority depending on the organization’s current requirements.
Identity establishes who is acting. Authority governs what the result may be.
Identity evidence links a proposed result to an actor. Authority evaluation separately asks whether that result falls within the organization’s established scope, limits, and conditions.
Identity systems provide evidence for the authority decision.
Relevant identity and security context supplied by existing controls.
Whether the result is within current authority, and a durable record of the determination.
Identity proofing, authentication, federation, access policy, endpoint security, and behavioral detection continue to provide their existing controls and signals. Authority Control can use relevant context from those systems while evaluating the consequential result.
Start with one actor and one consequential workflow.
Observe how a defined human, service account, workload, integration, or agent uses valid access to create organizational results, and what authority requirements would apply.