INVARIANCE | Arc
MenuClose
Identity and authority

A valid identity does not settle authority for the result.

Identity establishes who or what is acting. Access governs what it can reach. Authority Control evaluates whether the result is within current organizational authority.

The identity-consequence gap

The credential can be valid while the result exceeds authority.

A human, service account, workload, device, integration, or agent may be authenticated and permitted to reach a system. That still leaves a different question: what organizational results may this actor create through that access?

IdentityWho or what is acting?

Proofing, authentication, federation, claims, credentials, and accountable actor context.

AccessWhat may it reach?

Applications, APIs, data, workflows, systems, and technical operations.

Authority ControlWhat results may it create?

Payments, deployments, exports, deletions, approvals, transfers, filings, and other organizational results.

Actors Authority Control can evaluate

Organizational authority remains distinct from identity and access.

Human identities

Employees, contractors, officers, approvers, and operators.

Service and workload identities

Service accounts, integrations, workloads, devices, and automated pipelines.

AI agents

Agents acting under the scope and conditions established by the organization.

Actors under documented authorization

Automated actors operating under authority established by the organization.

The same identity can be associated with different authority depending on the organization’s current requirements.

Identity and authority

Identity establishes who is acting. Authority governs what the result may be.

Identity evidence links a proposed result to an actor. Authority evaluation separately asks whether that result falls within the organization’s established scope, limits, and conditions.

Relationship to IAM and Zero Trust

Identity systems provide evidence for the authority decision.

IAM and Zero Trust establish

Relevant identity and security context supplied by existing controls.

Authority Control establishes

Whether the result is within current authority, and a durable record of the determination.

Identity proofing, authentication, federation, access policy, endpoint security, and behavioral detection continue to provide their existing controls and signals. Authority Control can use relevant context from those systems while evaluating the consequential result.

Design partners

Start with one actor and one consequential workflow.

Observe how a defined human, service account, workload, integration, or agent uses valid access to create organizational results, and what authority requirements would apply.

The three lenses