LensReading which lens this session carries.

Delegated authority

Authority Register

Autonomy is only safe if somebody wrote down what each agent and each person is allowed to decide. This register is that document, and it is enforced: the decision route resolves a grant before it writes anything, and refuses when nothing covers the action.

Health

What the estate is currently allowed to do

Grants in force, who holds them, how often they are used and how often they are exceeded.

Grants
309
Across the estate
Active
309
Can authorize work now
Expired
0
Lapsed, needs renewal
Revoked
0
Withdrawn by an owner
Agent-held
154
Software may act alone
Human-held
155
A named person decides
Expiring 60d
52
Renew before the clock runs out
Breaches 30d
148
Attempts above the cap, refused

EN2-AUTH-H1

Chief Architect · Engineering · Architecture & Design

Anything the agent grant refuses, plus any override of an agent outcome. An override must state what the agent concluded and why it is being set aside.

Decision type
Approve, override and release held work on the architecture & design lines
Materiality cap
$2,000,000
Band
High
Jurisdictions
US · UK · DE · SG
Delegated from
Engineering leadership (Function leader)
Granted
2025-06-20
Expires
2027-04-04
Uses, last 30 days
227
Cap breaches, 30 days
0
Conditions attached
  • Cannot approve a unit the same person raised.
  • Override requires a written rationale citing the policy clause relied on.
  • Expiry is enforced, not advisory: an expired grant refuses.
If the cap is exceededThe action is refused and routed to the function leader with the attempted decision recorded.
Recent use in the evidence spine
1 evidence record cite this grant.

11 grants

Select any row to see the conditions, the delegation chain and how it has been used

Low 31Medium 104High 123Critical 51
ReferenceHolderDecision typeCapJurisdictionsDelegated fromExpiresUses 30dStatus
EN3-AUTH-H1
Build
Director, Platform Engineering
accountable-owner
Approve, override and release held work on the build lines$2,000kUS UK DE SG AUEngineering leadership2026-12-06114Active
EN4-AUTH-H1
Code Review & Quality
Director, Engineering Quality
accountable-owner
Approve, override and release held work on the code review & quality lines$25,000kUS UK DE SGEngineering leadership2026-10-0860Active
EN8-AUTH-H1
Technical Debt
Director, Engineering Effectiveness
accountable-owner
Approve, override and release held work on the technical debt lines$2,000kUS UK DE SGEngineering leadership2027-03-13170Active
EN5-AUTH-H1
Test & Assurance
Director, Quality Engineering
accountable-owner
Approve, override and release held work on the test & assurance lines$25,000kUS UK DEEngineering leadership2027-04-2790Active
EN9-AUTH-H1
Developer Experience
Director, Developer Platform
accountable-owner
Approve, override and release held work on the developer experience lines$25,000kUS UK DEEngineering leadership2026-09-21177Active
EN1-AUTH-H1
Portfolio & Intake
VP Engineering Operations
accountable-owner
Approve, override and release held work on the portfolio & intake lines$2,000kUS UK DE SGEngineering leadership2027-02-0441Active
EN2-AUTH-H1
Architecture & Design
Chief Architect
accountable-owner
Approve, override and release held work on the architecture & design lines$2,000kUS UK DE SGEngineering leadership2027-04-04227Active
EN7-AUTH-H1
Site Reliability
Director, Site Reliability
accountable-owner
Approve, override and release held work on the site reliability lines$25,000kUS UK DE SGEngineering leadership2027-04-22235Active
EN6-AUTH-H1
Release & Deployment
Director, Release Engineering
accountable-owner
Approve, override and release held work on the release & deployment lines$25,000kUS UK DE SG AUEngineering leadership2027-01-2515Active
EN11-AUTH-H1
Engineering Analytics
Director, Engineering Analytics
accountable-owner
Approve, override and release held work on the engineering analytics lines$2,000kUS UK DE SGEngineering leadership2027-06-27199Active
EN10-AUTH-H1
Security Engineering
Director, Security Engineering
accountable-owner
Approve, override and release held work on the security engineering lines$2,000kUS UK DE SG AUEngineering leadership2026-09-21114Active

How the register is enforced

Not a wall chart

When a decision is recorded, the route resolves a grant first: the right function, the right holder kind, an active status, a cap at or above the value at stake, and the jurisdiction of the work. If no grant covers all five, the route returns a refusal and writes a refusal record into the evidence spine. The decision does not happen.

Refusals are evidence in their own right. A cap breach that was stopped is worth more to an examiner than a clean run, because it shows the control fires.

Expiry is a real state, not a label. An expired grant authorizes nothing, which is why the sixty-day expiry tile matters more than the active count.

What is still missing

Say it before an examiner does

The holder identity on a grant is a name, not a cryptographic identity. Nothing here proves the actor was the actor. Signed agent identity and attestation are separate work and are not built.

The persona a user is browsing under is chosen in the interface and is not yet an identity the server trusts. The register is enforced against the value and the function; it is not yet enforced against a verified caller.

Delegation is one hop deep. A real board delegation chain runs several levels, with sub-delegation rules and counter-signatures. That depth is modeled as a single delegated-from field here.

Actions

What is waiting on a person

A grant is a written permission with an expiry, a cap and a named delegator. Nothing below renews itself.

Operations

What this desk is allowed to start

A surface that only reports is not operable. This is the work this page can set in motion, and the bound it runs into.

Trigger and bound

This desk can grant, narrow, extend or revoke a permission, and every one of those is written to the spine with the person who did it. It cannot let a holder act above the materiality cap on the grant: an attempt above the cap is refused at the point of decision and recorded as a breach rather than allowed and flagged afterwards.

Live observability

What the record shows right now

Grants split almost evenly between agents and people. 352,403 uses in the last thirty days produced 148 attempts above cap.

Current distribution

309 grants

Held by an agent15450%
Held by a person15550%

Is policy and strategy coming to fruition

Whether the written intent is holding here

148 cap breaches against 352,403 uses — 0% of exercised authority went past its bound.

Not holding on the record

The policy position is that no actor, agent or human, may commit the company past a stated value without a named delegator standing behind it. The record shows 309 active grants and 148 attempts above cap in thirty days, every one refused at the point of decision rather than allowed and reported later. That is the intent working. The part that is not proven is the ceiling itself: the caps were set by this team, not benchmarked against loss experience, so a grant being inside its cap says the rule held, not that the rule is right.