QIVREL / POSITION 001

When Authority Must Reach Execution

The practical boundary between automated decisions and protected actions

Qivrel Technologies Ltd | October 2026

The execution question

An automated system decides to act. It may deploy software, change access, modify infrastructure or initiate a transaction. The system has the capability to perform the operation. But what establishes that it has the authority to do so?

Capability is not authority. A decision to act does not, by itself, authorise execution.

The distinction matters wherever automated systems can initiate actions with practical consequences. AI agents are one example, but the question is wider than AI.

Authority must remain effective

Organisations assign authority through people, responsibilities, rules and technical controls. Automation need not require a person to approve every action. It does need to operate within the authority the organisation has established.

The practical test comes when a protected operation is about to take place. Do the conditions governing that operation still apply? An authorisation decision may be part of the answer. Its existence alone does not show that execution is controlled.

A negative authorisation result should be respected. Whether a control is effective must be established through evaluation of the particular environment, not assumed from its design.

That is why evidence needs a defined scope. We should be able to say what was tested, under which conditions, and what the result does and does not establish.

A shared engineering challenge

Identity, authorisation and policy enforcement are established fields of engineering. Existing approaches provide important foundations, including the separation of authorisation decisions from their enforcement. The question is not whether that distinction is new. It is what can be demonstrated about the control of a protected operation in a defined environment.

A design may describe where a decision is made and where it should be enforced. Evidence must address what actually happens within the scope being examined. That scope, and its limits, should be explicit.

Qivrel and QEG

Qivrel Technologies Ltd is an independent UK technology company developing proprietary technology concerned with execution authorisation.

QEG (Qivrel Execution Gate) is a proprietary, deterministic execution-authorisation technology. It is not an AI system. It is being developed for the authorisation of defined protected actions within specified system boundaries. Claims about its effectiveness must remain limited to the conditions and evidence actually examined.

QEG is one part of Qivrel’s broader work. We see value in automation that extends what people can do, without treating technical capability as a substitute for human and organisational responsibility.

Technical dialogue

Qivrel welcomes dialogue with research institutions, engineering organisations and technology developers interested in the evaluation of execution-authorisation controls.

We are interested in carefully bounded technical evaluations, including potential applications in software delivery and controlled automation. A useful starting point is to agree on the question to be tested, the evidence required and the limits of any conclusion. We also want to understand where this work may complement established approaches. Initial discussions can focus on the evaluation question without disclosing implementation details.

For an initial enquiry, please use the Dialogue contact form at qivrel.com. Confidential technical information should be shared only through separately agreed arrangements.

Qivrel Technologies Ltd | United Kingdom