Executive brief

The Authority Governance Control Plane for Agentic AI

A short brief on authority governance for AI agents: what agents are allowed to decide, why an inventory cannot answer that, and where enforcement has to sit.

Executive brief · Sep 2026PDF

The problem

AI agents are moving from answering questions to taking actions: approving requests, changing configurations, moving money, and committing the organization. The security stack governs identity (who the agent is) and access (what it can reach). Neither governs authority: what the agent is allowed to decide. An agent with valid credentials and valid permissions can still make a decision it was never authorized to make, and today no system defines, enforces, or records that boundary.

What BotAris does

BotAris is a governance layer that sits above identity and access. Organizations use it to define the decision rights delegated to each agent, enforce constraints at runtime before consequential actions execute, and account for every authority decision in a durable record built for auditors, regulators, and boards. It works with existing IAM investments and agent platforms rather than replacing them.

Authority = Decision Rights + Constraints + Accountability

Decision rights

What an agent is delegated to decide, by whom, and in what scope

Constraints

The limits, conditions, and thresholds that bound each decision

Accountability

An attributable, reviewable record of every decision made under delegation

Architecture overview

Agent layer

Agent Platformscopilots and orchestration frameworks
Custom Agentsin-house autonomous workflows
Embedded AIagents inside SaaS applications
Non-registered Agentsundiscovered and unmanaged
proposed actions

Control plane

BotAris Authority Governance Control Plane

Authority Modeldecision rights and constraints expressed as governed policy
Decision Authority Enforcement Point (DÆP)runtime evaluation of each proposed action against delegated authority in the agent's action path
Governed Authority Knowledge Basepolicies, decision taxonomies, authority templates, process constraints, escalation rules, approved control narratives
Accountability Ledgertamper-evident record of decisions, delegations, and outcomes
Governance Consoleoversight, management, administration
AllowConstrainEscalate to humanDeny
context and evidence

Enterprise fabric

Identity and IAMIdP, PAM, IGA, non-human identity
Approvals and ITSMhuman-in-the-loop escalation paths
SIEM and GRCevidence for audit, risk, and compliance

DÆP patterns

  • Decision Authority API
  • AgentGate Enforcement
  • API Gateway or Reverse Proxy
  • Sidecar or Service Mesh Enforcement
  • Tool Broker or MCP Gateway
  • Event-Only Decision Ledger Mode

Patent pending

Authority governance versus the adjacent market

CategoryWhat it governsDerived decision rightsLedgered ceilingsEscalation to the accountable humanPer-decision record
Identity governance (IGA)SailPoint, Saviynt, OktaAgent identity, ownership, and access lifecycleAdjacent capabilityNot in the data modelNot in the data modelAdjacent capability
Privileged access (PAM)Delinea, CyberArk, BritiveCredentials, sessions, and per-action privilegeAdjacent capabilityNot in the data modelAdjacent capabilityAdjacent capability
Platform estatesMicrosoft, ServiceNow, IBMAgents inside each vendor's own ecosystemAdjacent capabilityNot in the data modelNot in the data modelAdjacent capability
Machine identity and NHIAppViewX, Oasis (Cyera), Astrix (Cisco), Entro (SailPoint)Non-human identity inventory and secrets lifecycleAdjacent capabilityNot in the data modelNot in the data modelAdjacent capability
Next-generation IAMC1, NewCoreAgent-first identity with gateway-routed tool callsAdjacent capabilityNot in the data modelAdjacent capabilityAdjacent capability
Agent security startupsOnyx, Geordie, Noma, Zenity, HiddenLayerThreats: posture, prompt injection, runtime detectionAdjacent capabilityNot in the data modelAdjacent capabilityAdjacent capability
Runtime enforcementSondera, Archestra, AccuKnox, NightfallInline interception at the layer each ownsAdjacent capabilityNot in the data modelAdjacent capabilityAdjacent capability
GRC and AI governanceCredo AI, Holistic AI, HyperproofCompliance frameworks, programs, and evidenceNot in the data modelNot in the data modelNot in the data modelAdjacent capability
Authorization infrastructureCerbos, Oso, OpenFGA, OPARequest-time evaluation of hand-written policyAdjacent capabilityNot in the data modelNot in the data modelAdjacent capability
BotAris Authority GovernanceThe decision itself, at the moment it is proposedCore capabilityCore capabilityCore capabilityCore capability

✓ capability is core to the product. ◐ adjacent capability without an authority model behind it (attribution rather than derivation, per-action approval rather than escalation at an authority boundary, action logs rather than authority records). ✗ not in the data model. Ledgered ceilings means cumulative limits carried across a run; per-action thresholds without cumulative state do not count. Assessments are BotAris analysis of public vendor materials as of August 2026.

Why now

Agents are entering production

Enterprises are moving agents from pilots into workflows with real financial, operational, and legal consequences.

IAM was built for people

Identity and access categories assume human users and static service accounts, not autonomous software making judgment calls at machine speed.

Accountability is becoming mandatory

Boards, auditors, and emerging AI governance frameworks increasingly require organizations to show who authorized an automated decision and on what basis.

Contact

botaris.ai·6275 W Plano Pkwy, Suite 500, Plano, Texas 75093·+1.817.305.0658

Get in touch →