The Authority Governance Control Plane for Agentic AI
The problem
AI agents are moving from answering questions to taking actions: approving requests, changing configurations, moving money, and committing the organization. The security stack governs identity (who the agent is) and access (what it can reach). Neither governs authority: what the agent is allowed to decide. An agent with valid credentials and valid permissions can still make a decision it was never authorized to make, and today no system defines, enforces, or records that boundary.
What BotAris does
BotAris is a governance layer that sits above identity and access. Organizations use it to define the decision rights delegated to each agent, enforce constraints at runtime before consequential actions execute, and account for every authority decision in a durable record built for auditors, regulators, and boards. It works with existing IAM investments and agent platforms rather than replacing them.
Authority = Decision Rights + Constraints + Accountability
Decision rights
What an agent is delegated to decide, by whom, and in what scope
Constraints
The limits, conditions, and thresholds that bound each decision
Accountability
An attributable, reviewable record of every decision made under delegation
Architecture overview
Agent layer
Agent Platforms
copilots and orchestration frameworks
Custom Agents
in-house autonomous workflows
Embedded AI
agents inside SaaS applications
Non-registered Agents
undiscovered and unmanaged
Control plane
BotAris Authority Governance Control Plane
Authority Model
decision rights and constraints expressed as governed policy
Decision Authority Enforcement Point (DÆP)
runtime evaluation of each proposed action against delegated authority in the agent's action path
Governed Authority Knowledge Base
policies, decision taxonomies, authority templates, process constraints, escalation rules, approved control narratives
Accountability Ledger
tamper-evident record of decisions, delegations, and outcomes
Governance Console
oversight, management, administration
Enterprise fabric
Identity and IAM
IdP, PAM, IGA, non-human identity
Approvals and ITSM
human-in-the-loop escalation paths
SIEM and GRC
evidence for audit, risk, and compliance
DÆP patterns
- Decision Authority API
- AgentGate Enforcement
- API Gateway or Reverse Proxy
- Sidecar or Service Mesh Enforcement
- Tool Broker or MCP Gateway
- Event-Only Decision Ledger Mode
Patent pending
Authority governance versus the adjacent market
| Category | What it governs | Derived decision rights | Ledgered ceilings | Escalation to the accountable human | Per-decision record |
|---|---|---|---|---|---|
| Identity governance (IGA)SailPoint, Saviynt, Okta | Agent identity, ownership, and access lifecycle | Adjacent capability | Not in the data model | Not in the data model | Adjacent capability |
| Privileged access (PAM)Delinea, CyberArk, Britive | Credentials, sessions, and per-action privilege | Adjacent capability | Not in the data model | Adjacent capability | Adjacent capability |
| Platform estatesMicrosoft, ServiceNow, IBM | Agents inside each vendor's own ecosystem | Adjacent capability | Not in the data model | Not in the data model | Adjacent capability |
| Machine identity and NHIAppViewX, Oasis (Cyera), Astrix (Cisco), Entro (SailPoint) | Non-human identity inventory and secrets lifecycle | Adjacent capability | Not in the data model | Not in the data model | Adjacent capability |
| Next-generation IAMC1, NewCore | Agent-first identity with gateway-routed tool calls | Adjacent capability | Not in the data model | Adjacent capability | Adjacent capability |
| Agent security startupsOnyx, Geordie, Noma, Zenity, HiddenLayer | Threats: posture, prompt injection, runtime detection | Adjacent capability | Not in the data model | Adjacent capability | Adjacent capability |
| Runtime enforcementSondera, Archestra, AccuKnox, Nightfall | Inline interception at the layer each owns | Adjacent capability | Not in the data model | Adjacent capability | Adjacent capability |
| GRC and AI governanceCredo AI, Holistic AI, Hyperproof | Compliance frameworks, programs, and evidence | Not in the data model | Not in the data model | Not in the data model | Adjacent capability |
| Authorization infrastructureCerbos, Oso, OpenFGA, OPA | Request-time evaluation of hand-written policy | Adjacent capability | Not in the data model | Not in the data model | Adjacent capability |
| BotAris Authority Governance | The decision itself, at the moment it is proposed | Core capability | Core capability | Core capability | Core capability |
✓ capability is core to the product. ◐ adjacent capability without an authority model behind it (attribution rather than derivation, per-action approval rather than escalation at an authority boundary, action logs rather than authority records). ✗ not in the data model. Ledgered ceilings means cumulative limits carried across a run; per-action thresholds without cumulative state do not count. Assessments are BotAris analysis of public vendor materials as of August 2026.
Why now
Agents are entering production
Enterprises are moving agents from pilots into workflows with real financial, operational, and legal consequences.
IAM was built for people
Identity and access categories assume human users and static service accounts, not autonomous software making judgment calls at machine speed.
Accountability is becoming mandatory
Boards, auditors, and emerging AI governance frameworks increasingly require organizations to show who authorized an automated decision and on what basis.
Contact
botaris.ai·6275 W Plano Pkwy, Suite 500, Plano, Texas 75093·+1.817.305.0658
Get in touch