The AI doesn’t know who you are. Not your identity. Your authority.
Enterprises have spent two decades getting identity right. Single sign-on tells you who logged in. Role-based access controls tell you what category of user they are. Permissions matrices tell you what buttons they can click. The stack is mature, audited, and battle-tested.
So when AI enters the enterprise, the instinct is reasonable: plug it into the existing identity layer, scope its access, and move on.
That instinct misses something. Identity matters, but it answers a different question.
Identity answers: Who is this?
The question that matters once a system starts acting is different: Should this act, in this case, commit the organization?
That’s not identity. That’s authority.
Identity is access. Authority is commitment.
Organizations write authority down as grants: delegations, approval matrices, signing limits. Those grants are real, and they matter. But they don’t say whether any particular act falls within them. A signing limit tells you a VP may approve contracts up to $50K. It doesn’t tell you whether this contract should be approved. The grant is a boundary. The VP decided each case inside it.
Every system you run sees the boundary. None of them sees the deciding. So an AI plugged into those systems inherits the boundary, and nothing else.
Speed without ambiguity
There’s a fear hiding behind every agent conversation: “If we give AI authority, we lose control.”
That fear conflates authority with autonomy.
Authority doesn’t mean the system does whatever it wants. It means the act rests on a decision the organization can point to, with explicit requirements, known escalation paths, and enforceable constraints. The relationship is simple: models operate inside authority; they do not define it.
The usual shortcut is a wide grant: let the agent approve travel expenses under $500 for the APAC team through Q1. That buys speed by giving up the check. Every expense under $500 is now approved, including the ones a person would have questioned.
The alternative is to make the check itself something the agent can work under. The organization says what an expense decision needs: which receipts, which policy, what counts as unusual, who has to look when it is. The agent gathers the evidence and supplies judgment where it can. When the requirements are met, there is a decision, and the act can proceed on it. When they aren’t, the case waits for what’s missing instead of failing silently. The agent can be extremely autonomous where decisions exist and extremely conservative where they don’t. That comes from the architecture.
Without this structure, enterprises default to the only brake they have: more humans. More approvals. More review cycles. More friction. “Governance” becomes a synonym for delay, because the system can’t locate authority on its own.
The irony is that explicit authority enables speed. When a system can point to the decision behind an act, it doesn’t have to wait for confirmation. When requirements are structural rather than inferred, edge cases escalate cleanly instead of failing silently. When decisions are versioned and auditable, compliance stops being theater: screenshots and transcripts replaced by an actual chain of accountability.
Autonomy without authority is chaos. Authority without autonomy is bureaucracy. The balance requires structure that currently doesn’t exist.
Why this breaks now
For most of AI’s enterprise life, this gap didn’t matter. Summarization, drafting, recommendations: advisory work where a human always stood between the model and the commitment. If the model got something wrong, someone caught it before it mattered.
That person was doing more than catching errors. They were the one deciding, case by case, inside the grant. That buffer is disappearing.
Agents now book travel, process invoices, respond to customers, adjust pricing, onboard vendors, and modify systems of record. The moment AI moves from advising to acting, from words to commitments, authority stops being a governance nicety and becomes an operational requirement.
As usage scales, “minor” errors compound. As agents integrate into systems of record, blast radius stops being hypothetical. As enterprises face auditors and regulators, “the model seemed confident” stops being an acceptable answer.
The question enterprises will ask, are already asking, every single time something goes wrong: “Who authorized this?”
Today the answer is a person. With agents, a person is exactly what isn’t there. The answer has to become a decision: one a system can point to, made before the act, showing why this act was allowed.
Until AI systems can answer that by pointing to a machine-verifiable decision rather than a conversation transcript, they can’t cross the line from advisor to actor.
The architecture that’s missing
The fix isn’t complicated to describe. It’s a separation of concerns that enterprises already understand in other contexts:
The Model proposes and contributes: “I want to do X, and here is why.”
The Decision is established for this case, under requirements the organization sets: “X should happen, on this evidence, while these conditions hold.” The model’s judgment can be part of it. It can’t certify itself.
The Execution Layer acts only on authority derived from that decision, for that specific act. It checks that the conditions still hold when the act runs, alongside the identity and permission checks it already makes. If they don’t, the act doesn’t happen.
The model doesn’t check itself. It is checked against an external, machine-verifiable reference.
Enterprises already have authority structures: delegations, approval matrices, signing limits, policy hierarchies. They still matter. They say who may decide what, and within which limits. But the deciding happened in people, and what it relied on lives in SharePoint pages, PDF policies, email chains, tribal knowledge, and ad-hoc Slack approvals. To a human, that’s context. To a machine, it’s invisible.
The work isn’t making the grant readable to a machine. It’s turning the decision the person used to make inside the grant into something a system can establish, check, and act on.
The AI might know who you are. It might even know what you’re allowed to do.
It has no idea what you decided.