INVARIANCE | Arc
MenuClose
Across the enterprise

One determination. Different executive responsibilities.

Authority Control evaluates the proposed result before it takes effect. Finance, security, risk, and technology then use the determination and record for their respective responsibilities.

What it answers

Each function reads the determination through its own responsibility.

Each function uses the same determination and record to answer the questions within its responsibility.

Security

Which consequential results remain within authority under current conditions?

Access can remain valid while authority for a specific result is absent. The determination and its record state which results were within authority.

Risk

Where does material exposure exceed established authority or require resolution?

Review which results require additional authority, evidence, or resolution.

Finance

Are financial commitments within current delegated authority and limits?

Evaluate transfers, beneficiary changes, and obligations against current delegated authority and configured limits.

Operations

What can continue, what requires additional authority, and what should be held?

Where configured, selected results can be restricted while other activity remains permitted.

Technology and AI

What may systems and agents actually cause with the access and capability they hold?

Tool access and organizational authority over the result are separate questions.

Legal and compliance

What organizational authority supported the determination, and what evidence remains?

Each determination leaves a durable record for review.

Executive leadership

Are the organization’s most consequential activities operating within established authority?

A view across results, the authority that applies to them, and where additional authority is required.

Organizational authority is the common reference. Each function uses the determination within its existing responsibilities.

One record

How each function uses the determination.

Illustrative example: a treasury service proposes a beneficiary change outside its granted scope. Authority Control returns Block. On the integrated, enforcement-enabled path, the change does not proceed.

The determination and record stay constant while finance, security, risk, and technology use them for different responsibilities. How the evaluation works →

Where to start

Begin with one consequence.

Begin in observation on one workflow. Review what would receive Permit, Defer, or Block, then decide where validated enforcement adds value.