Services for Authority Graph adopters

Scoped review and integration work on delegated-authority systems, delivered by the project maintainer.

Authority model review

A written assessment of your delegation, approval and revocation model against Authority Graph’s documented invariants and known adversarial cases.

Deliverable
Written findings and prioritized recommendations.
Boundary
This is not a security certification of your system.

Integration support

Map your event history and authorization queries to the Authority Graph model, with explicit fixtures and reproducible tests.

Deliverable
Integration mapping, fixtures and implementation guidance.
Boundary
This does not include operating your production system.

Adversarial scenario session

A focused working session on confused-deputy paths, delegation laundering, revocation, approval replay and backdating in your architecture.

Deliverable
Facilitated session and written scenario summary.
Boundary
This is not a penetration test of third-party systems.

How an engagement works

Scope, deliverables, timeline and fees are agreed in writing before work begins.

What this is not

Authority is not currently offered as a self-service hosted product. No production operation, on-call service or security certification is included. No system is tested without written scope and prior authorization.

Project status

Authority Graph V0 · commit 6580fdf. Experimental, unaudited by an independent external human reviewer and not benchmarked at production scale.

Read the limits →

Provider

CAVEAUFLOW SASU, France. Remote engagements in English or French, under a written agreement and subject to limited capacity.

Project relationship

Authority Graph remains open source under Apache 2.0. Commercial services purchase scoped human work, not a separate proprietary edition.

Request a scoped engagement

Share the authority question, current architecture and expected decision timeline.

Request a scoped engagement →