INVARIANCE | Arc
MenuClose
Post-Breach Operations

Decide what may proceed while trust is uncertain.

Security teams may still be determining which identities, systems, or vendors can be trusted while critical operations must continue. Authority Control can apply tighter conditions to selected consequential results during that period.

When access can no longer be fully trusted, organizational authority can still limit which consequential results may take effect. Cyberattack Consequences asks what remains reachable through a compromised path. This page asks which results should remain permitted while investigation and recovery continue.

Where configured and integrated, tighter conditions can apply to major transfers, releases, and sensitive changes while other activity remains permitted. This does not make compromised access safe or replace incident response. Authority Control can help preserve selected authorized operations during degraded trust.

Where this sits

Existing security controls can isolate systems, revoke access, rotate credentials, segment networks, and contain an incident. Authority Control determines which business commitments may still proceed while those controls are operating.

Scale, scope, and pace

Degraded trust puts Scale, Scope, and Pace under pressure.

Many activities may continue across systems whose trust is uncertain, while conditions change during response. The organization must decide which results remain permitted.

The pressure under degraded trust
What stays stable

Scale

A large organization has many critical activities running at the same time, and broad shutdown carries its own operational cost.

What stays stable

Where configured, routine activity can remain permitted while tighter conditions apply to major transfers and sensitive changes.

Scope

The compromise may span identities, systems, vendors, and recovery tooling, and which of them can be trusted is not yet settled.

What stays stable

Consequential results may originate across several uncertain systems. Authority Control applies where the relevant workflows are integrated.

Pace

Conditions change through containment, recovery, and restoration, often hour by hour.

What stays stable

Organizations can apply tighter or broader operating conditions as the situation changes.

One authority model across the incident lifecycle

Keep critical operations moving under tighter conditions.

Identify the consequential workflows that may need tighter conditions during an incident and decide how unresolved cases will be handled.

Continues

A result within current authority may proceed. Permit

Waits

Selected high-consequence results wait for additional authority or resolution. Defer

Stops

A result outside authority does not proceed where enforcement is enabled. Block

As conditions improve, return toward normal operating conditions.

01

Keep essential work moving. Identify the consequential operations that need to continue during degraded trust.

02

Tighten selected results. Apply stricter conditions to higher-consequence activity where appropriate.

03

Use existing review. Route unresolved authority questions through the organization’s incident and approval processes.

04

Keep containment separate. Security controls remain responsible for isolation, credential action, and technical recovery.

05

Return toward normal operations. Adjust conditions through accountable organizational decisions as trust returns.

Complementary controls

Existing containment and selective authority control.

Existing security controls detect, investigate, revoke, isolate, segment, and remove threats. Authority Control governs which results active workflows may create while that work continues.

Infrastructure and access controls
  • Revoke or restrict credentials
  • Isolate a host or endpoint
  • Segment or shut down a network area
  • Suspend an application or vendor connection
  • Restore technical access
Authority Control
  • Apply tighter conditions to selected consequential results
  • Use Defer or Block when the authority question is unresolved or outside scope
  • Keep essential authorized workflows operating where appropriate
  • Rely on surrounding security controls for containment and technical recovery
  • Return toward normal conditions through accountable organizational decisions

Infrastructure controls constrain technical reach. Authority Control adds selective control over the organizational results that active workflows may create.

Boundary of the control

When segmentation is the stronger control.

Segmentation is the stronger response when the organization needs to stop or isolate broad technical activity, including lateral movement, malware communication, unintegrated commands, untrusted host behavior, or activity whose organizational result cannot yet be classified reliably.

Selective authority control may be useful when essential workflows remain active, their consequential results can be identified, and the relevant paths are integrated.

Segment the systems that cannot remain trusted. Apply Authority Control to the workflows that continue operating.

Worked scenario

Illustrative example: selective authority during an incident.

A large investment organization has credible evidence of compromise, but attribution remains incomplete. The activity may involve one or more service identities, AI-enabled workflows, sessions, or connected systems. Security teams continue identifying and containing the affected identities, workloads, and paths.

In this example, tighter conditions apply to selected financial, data, and automated results while security teams continue investigating.

Phase 1Uncertainty

Apply tighter conditions to selected high-impact actions while attribution remains uncertain.

Phase 2Localization

Adjust operating conditions as investigation and recovery progress.

Phase 3Restoration

Return toward normal operating conditions through accountable organizational decisions.

Illustrative configuration. The scopes, limits, and outcomes are defined by the organization.

Scope and dependencies

Detection, credential action, and technical recovery remain with connected security controls.

  • Connected security controls remain responsible for detecting and attributing compromise.
  • Credential restriction, isolation, and malware removal remain with surrounding controls.
  • Authority Control governs actions submitted through connected workflows that apply the determination.
  • Authority Control applies only on workflows where it is integrated.
  • Compromised access may remain dangerous. Authority Control addresses covered consequential results while security teams contain and recover.
See the canonical scope and dependencies on How it works →
Bounded design-partner engagements

Prepare the workflows that matter before an incident.

Identify consequential workflows that may need tighter conditions during an incident and assess where Defer or selective enforcement may help.