Ordinant

Library

The AI doesn't know who you are

Authority for an act has to come from a decision.

The AI doesn’t know who you are. Not your identity. Your authority.

Enterprises have spent two decades getting identity right. Single sign-on tells you who logged in. Role-based access controls tell you what category of user they are. Permissions matrices tell you what buttons they can click. The stack is mature, audited, and battle-tested.

So when AI enters the enterprise, the instinct is reasonable: plug it into the existing identity layer, scope its access, and move on.

That instinct misses something. Identity matters, but it answers a different question.

Identity answers: Who is this?

The question that matters once a system starts acting is different: Should this act, in this case, commit the organization?

That’s not identity. That’s authority.

Identity is access. Authority is commitment.

Organizations write authority down as grants: delegations, approval matrices, signing limits. Those grants are real, and they matter. But they don’t say whether any particular act falls within them. A signing limit tells you a VP may approve contracts up to $50K. It doesn’t tell you whether this contract should be approved. The grant is a boundary. The VP decided each case inside it.

Every system you run sees the boundary. None of them sees the deciding. So an AI plugged into those systems inherits the boundary, and nothing else.

Identity isn’t authority

Access control and authority look similar until you trace what happens when they fail differently.

Identity is comparatively stable. Authority is fluid:

  • Contextual: A VP can approve budgets up to a threshold, until a board resolution changes that limit.
  • Temporal: An “acting head of” can authorize in a narrow window, then instantly loses standing when the role is backfilled.
  • Revocable: A procurement officer’s SSO session might be valid for 12 hours, but their delegated signing authority could expire the minute they change teams.

The procurement officer’s SSO session doesn’t know about the delegation expiry. The VP’s role membership doesn’t encode the board resolution. The acting head’s access group doesn’t track the backfill date.

The people did. And they knew things no grant records: that this vendor failed an audit last year, that this request arrived through an unusual channel, that a contract this size needs legal to look first. Each of them checked what they knew against the case in front of them, usually without anyone seeing them do it. That check is where authority actually lived.

Most agent systems collapse all of this into a simple assumption: User = allowed actor. If someone can invoke the system, the system treats them as authorized to do whatever they’re asking.

The more careful designs go further. The agent gets its own identity. It acts on the user’s behalf through a delegated token, scoped to the task and expiring with it. That is good engineering, and it narrows what can go wrong. But look at what is being delegated. The token carries the person’s grant. It can’t carry what the person did with the grant: deciding, case by case, whether this act should happen. The boundary transfers. The deciding stays behind.

That works for access. It fails for commitment.

When a system can’t reference authority, it substitutes inference. It looks at what similar users did, what this user did last time, what seems reasonable given the context. That looks like competence until it becomes commitment, and by then, the organization has made a promise no one technically authorized.

Authority is not a prompt

This is the most tempting escape route, and the most dangerous.

The reasoning goes: if authority is the problem, encode the authority rules in the system prompt, fine-tune on policy documents, or give the agent memory of what’s allowed. The model is smart. It will follow the rules.

Consider what actually happens. A model sees a $75K vendor contract approval request. It observed this VP approve $50K contracts last quarter. The vendor uses similar language to previously approved vendors. The request came via the VP’s EA, who handles these routinely. Each signal looks reasonable. The model approves the contract.

None of that is authority. It’s pattern completion, what you might call simulated standing. The model generated the language of authorization without possessing the state of authorization. It sounds legitimate because sounding legitimate is exactly what language models do.

Any probabilistic system does this when a boundary condition is missing: it fills the gap with plausibility.

Prompts shape intent, but they don’t enforce constraints. Memory is narrative: it’s what the system thinks happened, not what was authorized. Fine-tuning adjusts probabilities, not permissions.

If the boundary can be rewritten by the model, it is not a boundary.

Now suppose you fix the obvious gap. You declare the VP’s limit explicitly: $50K, machine-readable, current. The model sees that $75K is over the line, and it escalates. Good. But make the contract $45K and ask again. The limit is satisfied. Is the contract approved? The limit never said so. It said who could decide. The VP used to read the terms, notice the vendor was new, and ask for the insurance certificate. Nobody encoded that, because the VP was there to do it.

A boundary is necessary. It isn’t sufficient. Something has to decide the case inside it, and the result has to be something a system can check. That is a decision: made about this case, under requirements the organization sets, whoever or whatever supplies the judgment. Authority for the act comes from it.

That decision, and the authority for the act that follows from it, must be a first-class system object with six characteristics:

  • Explicit: Declared and machine-verifiable, not inferred from text
  • External: Residing outside the model’s weights and context window
  • Inspectable: You can point to what was established, on what evidence, under which requirements
  • Versioned: You can audit exactly what applied at a specific point in history
  • Time-bound: The conditions it depends on are stated, and when they stop holding, so does the authority to act
  • Revocable: It can be withdrawn instantly without retraining or re-prompting

If you want an analogy that kills the “just prompt it better” conversation: think jurisdiction. You don’t ask a court to infer its jurisdiction from the arguments presented. You declare it, publish it, and enforce it before the case begins. Air traffic control doesn’t infer a no-fly zone from pilot chatter.

Or think about a police officer. The badge says who they are. The role says what kind of thing they may do. Neither lets them search your house. For that they need a warrant: issued by someone else, on evidence, for this address and these items, for a limited time. And it’s checked at the door. The officer’s authority to search comes from a decision about this case, not from being an officer.

In any serious domain, authority for a consequential act is a structural object, made before the act and checked when it happens. Not a suggestion in the input. And not a property of whoever happens to be acting.

Speed without ambiguity

There’s a fear hiding behind every agent conversation: “If we give AI authority, we lose control.”

That fear conflates authority with autonomy.

Authority doesn’t mean the system does whatever it wants. It means the act rests on a decision the organization can point to, with explicit requirements, known escalation paths, and enforceable constraints. The relationship is simple: models operate inside authority; they do not define it.

The usual shortcut is a wide grant: let the agent approve travel expenses under $500 for the APAC team through Q1. That buys speed by giving up the check. Every expense under $500 is now approved, including the ones a person would have questioned.

The alternative is to make the check itself something the agent can work under. The organization says what an expense decision needs: which receipts, which policy, what counts as unusual, who has to look when it is. The agent gathers the evidence and supplies judgment where it can. When the requirements are met, there is a decision, and the act can proceed on it. When they aren’t, the case waits for what’s missing instead of failing silently. The agent can be extremely autonomous where decisions exist and extremely conservative where they don’t. That comes from the architecture.

Without this structure, enterprises default to the only brake they have: more humans. More approvals. More review cycles. More friction. “Governance” becomes a synonym for delay, because the system can’t locate authority on its own.

The irony is that explicit authority enables speed. When a system can point to the decision behind an act, it doesn’t have to wait for confirmation. When requirements are structural rather than inferred, edge cases escalate cleanly instead of failing silently. When decisions are versioned and auditable, compliance stops being theater: screenshots and transcripts replaced by an actual chain of accountability.

Autonomy without authority is chaos. Authority without autonomy is bureaucracy. The balance requires structure that currently doesn’t exist.

What breaks when authority is missing

When authority isn’t a first-class system concern, you don’t get dramatic failure. You get quiet governance decay.

Authority drift: Escalation becomes statistically rare in the patterns the model learned from, so escalation stops happening. The system learns that most requests get approved, so it approves most requests.

Silent overreach: Boundaries are crossed with no alert because the boundary was never defined in a way the system can enforce. The model doesn’t know it’s overreaching because it has no reference for where the reach ends.

The orphaned commitment: Actions occur that no one can truthfully say were authorized. A commitment is made, and everyone assumes someone else was accountable.

The symptoms are consequences enterprises already recognize, but usually misdiagnose. AI takes actions no one technically authorized. Humans can’t explain why something was allowed; you get a post-hoc story, not a referenceable basis. Compliance becomes theater: screenshots and transcripts replace an actual auditable chain of authority.

This is the real reason enterprises hesitate on agentic AI. Not because they don’t trust models to produce good text. Because they can’t locate who is accountable when text turns into commitments.

The “trust” conversation goes nowhere because it’s misframed. The problem isn’t trust. The problem is unlocated authority.

Why this breaks now

For most of AI’s enterprise life, this gap didn’t matter. Summarization, drafting, recommendations: advisory work where a human always stood between the model and the commitment. If the model got something wrong, someone caught it before it mattered.

That person was doing more than catching errors. They were the one deciding, case by case, inside the grant. That buffer is disappearing.

Agents now book travel, process invoices, respond to customers, adjust pricing, onboard vendors, and modify systems of record. The moment AI moves from advising to acting, from words to commitments, authority stops being a governance nicety and becomes an operational requirement.

As usage scales, “minor” errors compound. As agents integrate into systems of record, blast radius stops being hypothetical. As enterprises face auditors and regulators, “the model seemed confident” stops being an acceptable answer.

The question enterprises will ask, are already asking, every single time something goes wrong: “Who authorized this?”

Today the answer is a person. With agents, a person is exactly what isn’t there. The answer has to become a decision: one a system can point to, made before the act, showing why this act was allowed.

Until AI systems can answer that by pointing to a machine-verifiable decision rather than a conversation transcript, they can’t cross the line from advisor to actor.

The architecture that’s missing

The fix isn’t complicated to describe. It’s a separation of concerns that enterprises already understand in other contexts:

The Model proposes and contributes: “I want to do X, and here is why.”

The Decision is established for this case, under requirements the organization sets: “X should happen, on this evidence, while these conditions hold.” The model’s judgment can be part of it. It can’t certify itself.

The Execution Layer acts only on authority derived from that decision, for that specific act. It checks that the conditions still hold when the act runs, alongside the identity and permission checks it already makes. If they don’t, the act doesn’t happen.

The model doesn’t check itself. It is checked against an external, machine-verifiable reference.

Enterprises already have authority structures: delegations, approval matrices, signing limits, policy hierarchies. They still matter. They say who may decide what, and within which limits. But the deciding happened in people, and what it relied on lives in SharePoint pages, PDF policies, email chains, tribal knowledge, and ad-hoc Slack approvals. To a human, that’s context. To a machine, it’s invisible.

The work isn’t making the grant readable to a machine. It’s turning the decision the person used to make inside the grant into something a system can establish, check, and act on.

The AI might know who you are. It might even know what you’re allowed to do.

It has no idea what you decided.