Authority Portal / Overview
JC
joe@acme.com
Employee
Authority workspace

Authority without the admin console.

One role-aware portal for employees, managers, application owners, AI operators and auditors. Request, use, approve, review and prove authority without exposing platform configuration.

6Active authorities
2JIT eligible
1Pending action
0Overdue reviews

What you can do here

Capabilities appear according to your role and ownership.

UseMy Authority

Understand what is approved and activate eligible temporary access.

GovernApprovals & Reviews

Make business decisions with usage and risk context.

ProveEvidence

Trace approved, provisioned and actually exercised authority.

Attention

Items relevant to your current role.

ERP Purchasing
Request awaiting approval
Production Support
JIT eligible · standing access zero
Finance Reporting
Authority aligned
My Authority

What you are authorized to do.

Business authority is shown separately from target access. An approved authority may remain active while standing target access remains zero.

AuthorityApplicationBusiness ownerTarget stateRuntimeStatus
Finance Reporting
Read & export approved reports
Finance AnalyticsFinance ControlStandingObservedActive
Production Support
Approved support authority
Cloud PlatformPlatform OpsZero · JIT eligibleInlineActivate
ERP PurchasingERPProcurementNot provisionedObservedPending
Request Authority

Request the business authority you need.

Request an application, role, business capability or bounded authority. Target entitlements are derived during fulfillment rather than being the business request itself.

New request

Describe the business need.

ApplicationERP Purchasing

Purchasing operations and approved transaction scope.

InfrastructureProduction Support

Time-bound operational support authority.

DataFinance Reporting

Reporting and approved data export capability.

Request context

Business justification and duration travel with the grant.

Ephemeral Authority

Keep the authority. Remove the standing access.

Activate temporary target access from an existing certified authority and return the provisioned state to zero when the work is complete.

Production Support

Temporary role activation

14:22

remaining

Finance Share

Session-bound authority

Inactive

Standing target access: zero

Cloud Deployment

Ephemeral token

Eligible

Runtime decision required

Lifecycle

T1Certified authorityPersistent
TRIGGERNeed arisesOn demand
T2Temporary accessMaterialized
T3ExecutionObserved / enforced
T2Return to zeroRevoked
Approvals

Decide with business and execution context.

Managers and owners approve authority, not obscure technical entitlements. Usage, conflicts and provisioning impact are shown before the decision.

RequesterAuthorityContextObserved useRecommendationAction
sarah@acme.comProduction SupportProject OrionPrior support activityJIT suitable
finance-agent-prodERP PurchasingAgent owner: FinanceBounded runtime activityOwner review
Certification

Review authority with evidence, not guesswork.

Recertification remains a first-class governance control. Runtime evidence and target state help owners decide whether authority should remain, change, move to JIT or be revoked.

24Due for review
7Evidence supports keep
5JIT candidates
3Dormant
SubjectAuthorityProvisionedExecutionSuggested action
john@acme.comCloud AdminStandingNo recent useConvert to JIT
billing-agentBilling APIScoped tokenRegular bounded useKeep
Application Owner

Govern authority for your applications.

Business-facing ownership view of requests, authority, target alignment and usage. Connector wiring remains in Console Pro.

ERP

Procurement · Business critical

94% aligned

11 active authorities · 2 findings

Finance Share

Finance · Restricted

JIT enabled

Standing access minimized

Sales CRM

Sales · Standard

Review due

6 authorities require certification

Agents & Workloads

See the authority boundaries of non-human identities.

Operators see active grants, ownership, runtime decisions and temporary credentials without gaining platform-administrator access.

IdentityOwnerAuthorityProvisioned stateRuntimeLast decision
finance-agent-prodFinance AutomationERP purchasing operationsEphemeralInlineAllowed
deploy-pipelinePlatform EngineeringProduction deploymentToken on demandObservedWithin authority
support-agentService OperationsSupport toolsScopedInlineBlocked
Authority Alignment

Source of truth versus reality.

A simplified governance projection of the Watchdog engine: what was approved, what exists in the target, and what authority was actually exercised.

T1 · APPROVEDProduction SupportCertified · owner valid
T2 · PROVISIONEDTemporary role activeJIT · time bound
T3 · EXECUTEDSupport actionWithin authority

AUTHORITY ALIGNED

SubjectComparisonFindingOwner action
john@acme.comT2 ↔ T3Dormant standing accessReview JIT conversion
support-agentT1 ↔ T3Runtime action outside authorityReview
Evidence Explorer

Trace authority from approval to execution.

Search an identity, application, authority or execution event and inspect the complete T1/T2/T3 lineage.

Evidence trace

T1 · Authority approved
Owner, purpose, scope, certification and policy version
T2 · Target state materialized
Provisioning source, target entitlement and validity window
T3 · Authority exercised
Observed action, runtime source, decision and timestamp
Reconciliation
Aligned · no unresolved exception

Assurance

Evidence is presented read-only to audit personas.

Authority aligned

Owner certified

Target state verified

Audit Exports

Package evidence for assurance and audit.

Create bounded evidence packages from authority, provisioning, execution, recertification and reconciliation history.

Evidence PackAuthority Trace

T1/T2/T3 lineage for selected identities, applications or controls.

CertificationReview History

Decision history, ownership, justification and evidence used.

ExceptionsFinding History

Detected drift, remediation, verification and closure.