LensReading which lens this session carries.

Delegated authority

Authority Register

Autonomy is only safe if somebody wrote down what each agent and each person is allowed to decide. This register is that document, and it is enforced: the decision route resolves a grant before it writes anything, and refuses when nothing covers the action.

Health

What the estate is currently allowed to do

Grants in force, who holds them, how often they are used and how often they are exceeded.

Grants
309
Across the estate
Active
309
Can authorize work now
Expired
0
Lapsed, needs renewal
Revoked
0
Withdrawn by an owner
Agent-held
154
Software may act alone
Human-held
155
A named person decides
Expiring 60d
52
Renew before the clock runs out
Breaches 30d
148
Attempts above the cap, refused

IT11-AUTH-A1

IT Finance Orchestrator · Information Technology · IT Financial Management

Any unit on a it financial management line where every intake check passed, the policy in force is current, and the value sits inside the cap below.

Decision type
Clear and route work on the it financial management lines
Materiality cap
$250,000
Band
Medium
Jurisdictions
US · UK · DE · SG · AU · FR
Delegated from
Director, IT Financial Management (Accountable human owner)
Granted
2025-10-02
Expires
2027-04-30
Uses, last 30 days
610
Cap breaches, 30 days
2
Conditions attached
  • Confidence at or above the line threshold, otherwise the unit is held.
  • Policy version in force must be current, not superseded.
  • Every action writes to the evidence spine before the unit advances.
If the cap is exceededThe action is refused at the decision interface, a refusal record is written to the spine, and the unit routes to the accountable human owner.

22 grants

Select any row to see the conditions, the delegation chain and how it has been used

Low 31Medium 104High 123Critical 51
ReferenceHolderDecision typeCapJurisdictionsDelegated fromExpiresUses 30dStatus
IT1-AUTH-A1
Service Desk
Service Desk Orchestrator
orchestrator
Clear and route work on the service desk lines$2,000kUS UK DE SG AU FR BRDirector, Service Desk2026-12-013607Active
IT1-AUTH-H1
Service Desk
Director, Service Desk
accountable-owner
Approve, override and release held work on the service desk lines$25,000kUS UK DE SG AU FR BRInformation Technology leadership2026-09-25192Active
IT6-AUTH-A1
Application Management
Application Management Orchestrator
orchestrator
Clear and route work on the application management lines$250kUS UK DE SGDirector, Application Services2026-11-031517Active
IT6-AUTH-H1
Application Management
Director, Application Services
accountable-owner
Approve, override and release held work on the application management lines$2,000kUS UK DE SGInformation Technology leadership2026-12-03227Active
IT10-AUTH-A1
Change & Release
Change Orchestrator
orchestrator
Clear and route work on the change & release lines$2,000kUS UK DE SG AUDirector, Change Management2027-04-042742Active
IT10-AUTH-H1
Change & Release
Director, Change Management
accountable-owner
Approve, override and release held work on the change & release lines$25,000kUS UK DE SG AUInformation Technology leadership2027-06-1035Active
IT8-AUTH-A1
Data & Integration Platform
Data Platform Orchestrator
orchestrator
Clear and route work on the data & integration platform lines$250kUS UK DE SG AUDirector, Data Platform2026-09-133602Active
IT8-AUTH-H1
Data & Integration Platform
Director, Data Platform
accountable-owner
Approve, override and release held work on the data & integration platform lines$2,000kUS UK DE SG AUInformation Technology leadership2027-01-2059Active
IT2-AUTH-A1
Identity & Access
Identity Orchestrator
orchestrator
Clear and route work on the identity & access lines$2,000kUS UK DE SGDirector, Identity & Access Management2027-01-172328Active
IT2-AUTH-H1
Identity & Access
Director, Identity & Access Management
accountable-owner
Approve, override and release held work on the identity & access lines$25,000kUS UK DE SGInformation Technology leadership2026-09-2682Active
IT4-AUTH-A1
Infrastructure & Cloud
Infrastructure Orchestrator
orchestrator
Clear and route work on the infrastructure & cloud lines$2,000kUS UK DE SGDirector, Cloud Infrastructure2027-01-114084Active
IT4-AUTH-H1
Infrastructure & Cloud
Director, Cloud Infrastructure
accountable-owner
Approve, override and release held work on the infrastructure & cloud lines$25,000kUS UK DE SGInformation Technology leadership2026-09-2285Active
IT3-AUTH-A1
End-User Compute
End-User Compute Orchestrator
orchestrator
Clear and route work on the end-user compute lines$250kUS UK DE SG AU FR BRDirector, Workplace Technology2026-12-061630Active
IT3-AUTH-H1
End-User Compute
Director, Workplace Technology
accountable-owner
Approve, override and release held work on the end-user compute lines$2,000kUS UK DE SG AU FR BRInformation Technology leadership2026-10-07180Active
IT5-AUTH-A1
Network
Network Orchestrator
orchestrator
Clear and route work on the network lines$250kUS UK DE SG AUDirector, Network Services2027-06-092011Active
IT5-AUTH-H1
Network
Director, Network Services
accountable-owner
Approve, override and release held work on the network lines$2,000kUS UK DE SG AUInformation Technology leadership2027-06-13146Active
IT7-AUTH-A1
Cybersecurity Operations
Security Operations Orchestrator
orchestrator
Clear and route work on the cybersecurity operations lines$2,000kUS UK DE SG AU FRDirector, Security Operations2026-11-153165Active
IT7-AUTH-H1
Cybersecurity Operations
Director, Security Operations
accountable-owner
Approve, override and release held work on the cybersecurity operations lines$25,000kUS UK DE SG AU FRInformation Technology leadership2027-01-17108Active
IT9-AUTH-A1
Asset & License
Asset Orchestrator
orchestrator
Clear and route work on the asset & license lines$2,000kUS UK DEDirector, IT Asset Management2026-12-25453Active
IT9-AUTH-H1
Asset & License
Director, IT Asset Management
accountable-owner
Approve, override and release held work on the asset & license lines$25,000kUS UK DEInformation Technology leadership2026-11-17128Active
IT11-AUTH-A1
IT Financial Management
IT Finance Orchestrator
orchestrator
Clear and route work on the it financial management lines$250kUS UK DE SG AU FRDirector, IT Financial Management2027-04-30610Active
IT11-AUTH-H1
IT Financial Management
Director, IT Financial Management
accountable-owner
Approve, override and release held work on the it financial management lines$2,000kUS UK DE SG AU FRInformation Technology leadership2026-12-2461Active

How the register is enforced

Not a wall chart

When a decision is recorded, the route resolves a grant first: the right function, the right holder kind, an active status, a cap at or above the value at stake, and the jurisdiction of the work. If no grant covers all five, the route returns a refusal and writes a refusal record into the evidence spine. The decision does not happen.

Refusals are evidence in their own right. A cap breach that was stopped is worth more to an examiner than a clean run, because it shows the control fires.

Expiry is a real state, not a label. An expired grant authorizes nothing, which is why the sixty-day expiry tile matters more than the active count.

What is still missing

Say it before an examiner does

The holder identity on a grant is a name, not a cryptographic identity. Nothing here proves the actor was the actor. Signed agent identity and attestation are separate work and are not built.

The persona a user is browsing under is chosen in the interface and is not yet an identity the server trusts. The register is enforced against the value and the function; it is not yet enforced against a verified caller.

Delegation is one hop deep. A real board delegation chain runs several levels, with sub-delegation rules and counter-signatures. That depth is modeled as a single delegated-from field here.

Actions

What is waiting on a person

A grant is a written permission with an expiry, a cap and a named delegator. Nothing below renews itself.

Operations

What this desk is allowed to start

A surface that only reports is not operable. This is the work this page can set in motion, and the bound it runs into.

Trigger and bound

This desk can grant, narrow, extend or revoke a permission, and every one of those is written to the spine with the person who did it. It cannot let a holder act above the materiality cap on the grant: an attempt above the cap is refused at the point of decision and recorded as a breach rather than allowed and flagged afterwards.

Live observability

What the record shows right now

Grants split almost evenly between agents and people. 352,403 uses in the last thirty days produced 148 attempts above cap.

Current distribution

309 grants

Held by an agent15450%
Held by a person15550%

Is policy and strategy coming to fruition

Whether the written intent is holding here

148 cap breaches against 352,403 uses — 0% of exercised authority went past its bound.

Not holding on the record

The policy position is that no actor, agent or human, may commit the company past a stated value without a named delegator standing behind it. The record shows 309 active grants and 148 attempts above cap in thirty days, every one refused at the point of decision rather than allowed and reported later. That is the intent working. The part that is not proven is the ceiling itself: the caps were set by this team, not benchmarked against loss experience, so a grant being inside its cap says the rule held, not that the rule is right.