One governance model, applied everywhere.
Permissions, policies, approvals and audit set and applied consistently across the platform - so the same controls govern work wherever it happens.
Governance fragments when the work does.
Permissions might sit in one application, approvals in another, policies in process documents and evidence in an audit log. Once work crosses those boundaries, it becomes harder to prove that the same controls were applied consistently.
That leads naturally to the platform proposition.
Being allowed to act does not mean the action should proceed.
Identity is only the first question. Governance must also evaluate where the action applies, which policies govern it and whether its context requires stronger control before the work can continue.
The questions every action must answer
Identity - Is this actor entitled to perform the action?
Scope - Are they acting on the right organisation, account, entity or record?
Policy - Does the action satisfy the rules for this context?
Risk - Does the surrounding behaviour require stronger control?
One model evaluates the action
Authorisation is evaluated per action, resource and context.
The same framework covers people, systems, workflows and agents.
Approval lifecycles gate the action itself rather than relying on reminders.
Risk policies can escalate an action the identity is otherwise allowed to take.
The decision, reason and applied control are preserved as evidence.
One control path for every action.
Authenticate
Establish the identity behind the request - whether a person, system or an AI agent.
Authorise
Confirm permission to perform the action against the requested resource and scope.
Apply requirements
Evaluate policy and risk to determine additional controls and approvals for the action.
Execute
Perform the action recording the decision and outcome.
Who starts the work can change. The controls do not.
Context based authority.
Broad roles in software rarely reflect how responsibility is divided across a real organisation. Abaci evaluates authority against the context of each action, allowing access to be scoped at the right level.
Organisation
Apply authority across an entire organisational boundary.
Account
Limit authority to a particular business, service or operational context.
Entity
Grant authority for specific legal entities, clients or other governed scopes.
Record
Restrict authority to the individual records or resources involved.
Flexible combinations
Combine scopes to reflect the way responsibility is actually divided across the organisation.
Evaluated at action time
The relevant scope is checked when the action is authorised, not assumed from general platform access.