Execution Authority · Pattern library
The same risky actions, in every company.
A pattern is a shape of risky execution that recurs regardless of industry — an action that spends money nobody approved, a deploy that assumes a review it never had, an agent that reaches data it should not keep. 15 patterns, each with the signals that decide it and, where the evaluator ships one, the policy pack whose rules decide it.
Showing the patterns that most often bite in Public sector. They are the same patterns — the filter narrows the library, it does not change what a pattern is.
Protecting money
Payments, payouts, refunds, spend and treasury movement.
Protecting code
Deploys, migrations, branches and release gates.
Protecting infrastructure
Production data, cloud resources, secrets and network egress.
Protecting approvals
Delegated authority, segregation of duties and escalation paths.
Protecting identity
Access grants, privilege, offboarding and who may act for whom.
Browse by concept instead
Each pattern belongs to one or more concepts. If you arrived with a term rather than a workflow, start there.
- Permission Fatigue
- AI Approval
- Policy Engine
- AI Spending
- MCP Security
- Agent Permissions
- Independent Execution Authority
- Execution Control
- AI Egress Control
- Policy as Code
- Execution Governance
- Agent Permission Scope
- Approval Evidence
- Pre-Execution Authorization
- Approval Bypass
- Checkout Validation
- Agent Refund Limits
- Merchant Controls for Agent Orders
