Arc I · Security · Post-Breach Containment
Post-Breach Containment

Keep the institution operating. Narrow what compromised access can commit.

During a suspected compromise, an institution can keep essential operations running while it reduces the authority available through governed workflows. Access associated with the compromise may persist while attribution remains incomplete, but the authority available through that access can remain bounded and be narrowed further.

Where this sits

Existing security controls detect, investigate, and remove threats. Authority Control limits what valid, stolen, or uncertain access may commit while that work continues.

Worked scenario

One institution, mid-incident.

A large investment organization has credible evidence of compromise, but attribution remains incomplete. The activity may involve one or more service identities, AI-enabled workflows, sessions, or connected systems. Security teams continue identifying and containing the affected identities, workloads, and paths.

When attribution is incomplete, the institution can face a coarse tradeoff between leaving broad access available and restricting legitimate operations along with the suspected activity. Authority Control adds a consequence-level response: activate an incident-narrowed posture across selected financial, data, and automated commitment classes while essential activity continues.

Phase 1Uncertainty

Apply broad narrowing across selected consequence classes before the affected actor is confirmed.

Phase 2Localization

As evidence points to a workflow or identity, tighten controls there and relax them where confidence returns.

Phase 3Restoration

Return authority in deliberate steps, with each change attributed and recorded.

Illustrative configuration. Actual authorized scopes, cumulative limits, escalation paths, and outcomes are defined by the organization.

Broad activation, precise effect

The posture can be broad. The determinations remain fine-grained.

Limit high-consequence activity across governed workflows while attribution remains incomplete.

The institution can narrow selected financial, data, and automated commitment classes before it knows exactly which identity or workflow is compromised. Each request still resolves according to its action, amount, purpose, destination, conditions, cumulative exposure, and authority path.

Operating conditions during incomplete attribution
  • Same institution
  • Same operating environment
  • Attribution still incomplete
  • Technical access under investigation
  • Security containment continuing
AttributionStill incomplete
Security responseInvestigating identities, sessions, workloads, and paths
Authority responseNarrowing selected consequence classes across governed workflows
Continuity pathDefer routes legitimate exceptions for additional accountable authority

Financial operations

Selected financial commitment class under an institution-wide incident posture
Permit preserves routine operations.

The action proceeds within the current authorized scope and conditions.

Defer keeps a governed path open.

The action waits for additional authority, information, review, or escalation, then returns for evaluation.

Block closes the current path.

The action has no route forward under the current configuration.

Normal Defer can become more stringent during a breach.

Under normal operations, a material trade may require a portfolio lead and risk officer. Under an incident-narrowed posture, the same action may require a higher authority, multiple independent approvers, stronger verification, or additional evidence.

The additional path should add authority or evidence meaningfully independent of the original request. The original credential or authority alone is no longer sufficient. A deferred request proceeds only after the required inputs are supplied, recorded, and successfully evaluated.

Illustrative configuration. The organization defines its actual authorized scopes, cumulative limits, roles, evidence requirements, escalation paths, and outcomes.

Two independent limits

Access is one limit. Authority is another.

Security and access controls govern whether an identity can reach a system or a dataset. Authority Control governs what consequences that identity may create through it. The two limits are set separately, so the institution can hold access steady while it narrows authority.

Access, governed by security controls

Can this identity reach the system?

  • Identity, device, and session context
  • Network reachability and workload access
  • Whether the credential remains valid
  • Whether the connection is permitted
Authority, governed by Authority Control

Is this action within the institution’s authorized scope?

  • Consequence-specific authorized scopes
  • Cumulative-limit evaluation across actions
  • Permit, Defer, or Block determinations
  • A durable record of the authority basis for each

Access associated with the compromise may persist while attribution remains incomplete, but the authority available through that access can remain bounded and be narrowed further.

Composition with security and Zero Trust

Security restricts access as evidence develops. Authority Control limits high-consequence actions while the investigation continues.

Security and Zero Trust contribute

Locating and containing the compromise

  • Identity, device, and session context
  • Network and behavioral signals
  • Threat posture and signs of lateral movement
  • Credential and access actions
Authority Control contributes

Bounding what the affected workflow can commit

  • The current authority picture and authorized scopes
  • Cumulative-limit evaluation
  • Permit, Defer, or Block determinations
  • A durable record of narrowing, exceptions, and restoration

Security and Zero Trust identify and restrict affected access as evidence develops. Authority Control limits high-consequence actions across governed workflows while lower-risk operations continue.

Authority Observation Mode

See how authority operates. Prepare how it should narrow.

Authority Observation Mode evaluates and records governed activity without controlling downstream execution. It shows where consequential authority is exercised, where exposure accumulates, and how proposed Permit, Defer, and Block configurations would affect legitimate operations.

Function AMap current authority

Identify the identities, workflows, actions, amounts, destinations, and cumulative patterns creating organizational consequence.

Function BDesign Defer paths

Determine which legitimate high-consequence actions need a governed route forward and what additional independent authority or evidence they require.

Function CReview proposed narrowing

Use observed activity and structured scenario analysis to review how proposed Permit, Defer, and Block settings could affect continuity, escalation volume, and accountable roles.

Function DRefine and restore

Continue observing alongside enforcement so the institution can adjust as evidence develops and prepare deliberate restoration.

Observed actionNormal configurationProposed incident configuration
$25M tradePermitDefer to portfolio lead and risk officer
$75M tradeDefer through ordinary approvalDefer to higher independent authority and stronger verification
New settlement destinationDeferBlock
Large data exportPermit within normal limitsDefer to data owner and compliance
AI consequential executionPermit within approved scopeDefer to accountable human authority

Illustrative proposed configuration informed by Authority Observation Mode findings. AOM supplies operational evidence. The organization defines the authority response.

Activation is a governed pivot.

An accountable operator decides when a proposed configuration controls execution. Authority Observation Mode can continue alongside selective enforcement, supporting further adjustment, review-load analysis, and restoration.

Governance of the response

Narrowing is governed, not improvised.

The incident posture is a deliberate change to the authority configuration. Each change carries the same discipline as the commitments it governs.

  • 1
    An accountable operator activates the posture

    Entering the incident-narrowed posture is an explicit, attributed action informed by observed activity and prepared response patterns.

  • 2
    Narrowing may differ by domain

    Financial, data, and automated authority can be narrowed independently.

  • 3
    Deferred actions return for evaluation

    A deferred request proceeds only after the required authority, information, review, or escalation is supplied, recorded, and successfully evaluated.

  • 4
    Configuration changes are themselves governed

    Changing the authority posture requires additional accountable authority.

  • 5
    Restoration is deliberate and recorded

    Authority returns in defined steps, each attributable after the fact.

  • 6
    The record informs future preparation

    The durable record of this incident shapes the narrowing patterns prepared for the next.

Scope

What this does, and what it does not.

Honest boundary

Authority Control does not detect malware, revoke credentials, remove an attacker, or govern unintegrated technical paths. Within governed workflows, it determines which commitments may proceed and records the authority basis for each determination.

It does not authenticate identities, detect identity compromise, or replace identity-security systems, incident response, endpoint security, IAM, DLP, or threat detection. Compromised access does not become safe. What narrows is the authority available to turn that access into a consequential organizational outcome.

Engagement

Post-Breach Containment Assessment.