Mission Intelligence Systems

AI Transformation · Authority

Authority Should Expire

An agent can be properly authorized at nine in the morning and unsafe by noon. Most governance models have no way to express the difference.

Key Takeaways

  • Authority is granted as though it were a property of a person or a system. It is a conditional grant, safe only while the assumptions behind it hold, and organizations almost never write those assumptions down.
  • When the assumptions change and the grant does not, governance can only verify that an authorization once existed. It cannot ask whether the authorization is still valid, because nothing in the record says what it depended on.
  • The repair is a set of expiry conditions decided at the moment of granting: what would make this unsafe, how we would detect it, who can suspend it, and what evidence restores it.

Access, authority, and continuing authority

Three things get treated as one. Access is whether a system or a person can technically reach something. Authority is whether they are entitled to act on it. Continuing authority is whether that entitlement still holds under conditions that have changed since it was granted. Organizations invest heavily in the first, moderately in the second, and almost nothing in the third.

The distinction is not new. Saltzer and Schroeder set out the design principles for protection in computer systems in 1975, and one of them was complete mediation: every access must be checked against current authority, not against a decision cached from an earlier one. Half a century later, most organizational authorization is precisely that cached decision. An approval is granted once, recorded, and treated as settled, and the record of it becomes the evidence that governance happened.

Why a valid authorization becomes unsafe

Nothing has to go wrong for a correct authorization to become a dangerous one. Jens Rasmussen described the mechanism in 1997: organizations under pressure for efficiency migrate toward the boundary of safe operation, not through any single decision but through an accumulation of locally reasonable ones. Charles Perrow had already argued that tight coupling turns small changes into fast ones. James Reason called the residue latent conditions, faults built into the system long before anyone acts on them.

None of that literature is about AI, which is the point. The pattern is old, and organizations have always absorbed it because the timescale was forgiving. A person granted approval authority for a class of spend drifts out of the assumptions behind it over years, and a reorganization eventually catches it. An autonomous system does the same drift in an afternoon, at a volume no review cycle was designed to follow.

The asymmetry that makes this urgent

The authorization is static and everything it depended on is dynamic. Cost per action falls, data scope widens, a policy is rewritten, a model is upgraded, a dependency is swapped. Every one of those moves the ground under a grant that nobody re-examines, because nothing in the organization is set to ask.

The six triggers that should force reauthorization

A trigger is a named change that ends the grant until someone renews it. Each needs a threshold decided in advance, because a trigger with no number is a preference, and preferences do not fire.

01

Cost

Cost per action moves outside the envelope the grant assumed. A workflow authorized when an action cost a fraction of a cent is a different commitment when volume rises or pricing changes, and the authorization says nothing about volume.

02

Risk class

What is being acted on changes category. The same automation pointed at internal drafts and at customer commitments is not the same automation, and the grant almost never names the class it was scoped to.

03

Data scope

The system can now see or act on data it could not when the grant was made. Scope widens quietly, through an integration, a permission inheritance, or a source that changed what it contains.

04

Policy

An internal policy, a contractual obligation, or a regulation changes. The authorization was compliant against a rule that no longer reads the same way, and nothing connects the two records.

05

Time

Enough time has passed that the assumptions are unexamined rather than validated. Time is the weakest trigger and the only one that fires without anyone noticing a change, which is exactly why it is worth having.

06

Scope of action

The set of things the system can do has grown, through a new tool, a new integration, or a capability that arrived with a model upgrade nobody treated as a governance event.

Who owns the renewal

Four verbs, and they are not the same decision. To renew is to re-examine the assumptions and find them still holding. To narrow is to keep the grant with a smaller scope. To suspend is to stop it immediately, pending evidence. To revoke is to end it. Suspension is the one that has to be exercisable by a single named person without convening anything, and it is the one most organizations have never tested.

Ownership follows the same rule as any other decision right: it sits where the knowledge is, not where the rank is. Herbert Simon's observation that a decision is made well where knowledge and authority meet applies exactly as well to the decision to withdraw an authority as to the decision to grant it, and organizations routinely put the two in different places. The grant is made by a governance body and the first sight of the assumption breaking belongs to an operator who cannot act on it.

The Authority Expiration Test

Take one authorization currently in force, for a person or for a system, and answer five questions.

  1. 1.What assumptions made this authority safe when it was granted?
  2. 2.Which changes would invalidate those assumptions?
  3. 3.How will the organization detect those changes?
  4. 4.Who can suspend the authority immediately, without a meeting?
  5. 5.What evidence is required before it is restored?

If the first question needs a meeting to answer, the grant was never conditional. If the fourth needs a meeting, there is no suspension, only a proposal to suspend.

What a board should be able to see

The oversight standard is not a good outcome. It is a system that produced information and a record that the body used it. For authority that means three artifacts a board can actually ask for: the conditions each material grant depends on, the detection that watches those conditions, and the log of what has been renewed, narrowed, suspended or revoked, with the reason. An organization that can produce the first two and has an empty third has not been lucky. It has not been watching.

Evidence matrix

Established byThe findingWhat it bears on
Saltzer and Schroeder (1975)Complete mediation: every access checked against current authority, never a cached decision.Why a recorded authorization is not evidence of a current one.
Rasmussen (1997)Systems migrate toward the boundary of safe operation under efficiency pressure, with no single decision to do so.Why nothing has to go wrong for a valid grant to become unsafe.
Perrow (1984); Reason (1997)Tight coupling propagates change quickly; latent conditions accumulate unseen.Why the timescale, not the mechanism, is what agentic systems changed.
Jensen and Meckling (1976)Delegation to an agent whose actions cannot be fully observed requires bounding and monitoring.Why revocation is part of the grant rather than an escalation.
Simon (1947)A decision is made well where knowledge and authority meet.Where the right to suspend has to sit.
NIST SP 800-207 (2020)Zero trust: trust is never granted implicitly and must be continually evaluated.That continuous reauthorization is an established architecture, not an aspiration.

The Four A's reading

This is an Authority condition, and a precise one. The Four A's ask whether decisions are made at the right level with enough speed. Expiring authority adds the dimension that question leaves implicit: whether a decision made at the right level once is still being made there now. An organization can pass every static test of decision rights and still hold hundreds of grants whose conditions dissolved without anyone being assigned to notice.

It also touches Attention, because detection costs something and an organization with no margin will not staff it, and Adaptability, because the ability to narrow a grant rather than choosing between renewal and revocation is what lets a system keep operating while it is corrected.

DF

About the Author

Dan Flynn

Creator of The Four A's of Organizational Readiness™ · Enterprise Transformation Executive · Author, Builders Build

Dan Flynn has spent thirty years inside federal, defense, and commercial organizations: diagnosing the invisible conditions that determine whether capable people produce extraordinary results. He is the creator of The Four A's of Organizational Readiness™ framework, has reached more than 11,000 professionals across corporate, civic, and national security contexts, and took a federal data platform from one release every six months to seventy-two every two weeks by changing organizational conditions: not people.

His book, Builders Build: The Four A’s of Organizational Readiness™, is forthcoming.