Governance

Why approvals and audit logs cannot live in a separate tab

Governance fails when identity, authority, policy, approval, evidence, and audit live in separate tools instead of on the action itself.

Effective
Last updated
Reading time
7 min

From September 28 to October 17, 2023, an intruder sat inside Okta's customer support system. The attacker downloaded support files that customers had uploaded. Some files contained live session tokens. Those tokens were then used to hijack downstream customer sessions, including customers like BeyondTrust and Cloudflare.

The uncomfortable part is that Okta is the company many enterprises use to govern identity.

This was not only an identity failure. It was a workflow failure. A service account had access. A support export contained sensitive tokens. A file could be downloaded. The policy that should have blocked the action did not follow the action. The audit trail existed, but the important pieces lived in different systems.

That is the governance problem: companies buy tools for identity, approvals, privacy, audit, compliance, and AI governance, but the action itself often does not carry the proof.

The dashboard is not the control

The last decade of governance software turned binders into dashboards. That was useful.

Vanta and Drata collect SOC 2 and ISO evidence. OneTrust and Transcend manage privacy workflows. Okta manages identity. Permit.io and OPA-based tools handle authorization. SIEM tools collect logs. AI governance tools now add another dashboard for model risk.

The problem is that dashboards often govern after the fact. They collect evidence about an action after the action happened. They do not necessarily stop the action. They do not always know which policy applied. They do not always know who approved it. They often cannot connect the action, policy, evidence, approval, and audit record without manual reconstruction.

That is why compliant companies still get breached. SOC 2 proves controls existed. It does not prove every important action carried the right control at the moment it happened.

Why this matters outside security

Governance sounds like a security or compliance problem. In operating companies, it is also a speed problem.

When approvals are unclear, good teams slow down. A marketer waits before launching a price test because they are not sure who can approve it. A finance operator waits before reconciling a refund batch because the supporting evidence is scattered. An agency waits before changing budget because the spend cap lives in a Slack thread. A support lead waits before letting an AI assistant answer policy questions because nobody can prove which policy version it used.

The alternative is worse: the team moves fast and reconstructs the proof later. That works until a customer complains, an auditor asks, a refund policy is challenged, a regulator reviews an AI decision, or a board asks why spend moved without approval.

Good governance should not make every action slow. It should make the allowed path obvious. If the action is low-risk and inside policy, it should move quickly. If it crosses a threshold, it should request approval. If the evidence is missing, it should refuse to write. That is different from a dashboard that reports on controls after the fact.

What every important action should carry

Every consequential action should carry six fields.

Identity. Who acted? A person, service account, workflow, or AI agent should resolve to a specific identity.

Authority. Was that actor allowed to do this? The action should point to the role or permission that allowed it.

Policy. Which rule applied? A refund policy, data-retention policy, access policy, AI-use policy, or approval policy should be versioned and referenced.

Approval. Who approved the action, if approval was required? If no approval was required, the action should show the rule that made it automatic.

Evidence. What facts justified the action? The ticket, customer record, document, experiment result, order, or prior message should be attached as references, not recreated later from memory.

Audit event. What permanent record was written? The event should be stored with a trace ID so someone can reconstruct the action later without screenshots and Slack archaeology.

These are normal business questions. The problem is that most stacks answer them in six different tools.

Where the old model breaks

The old model assumes governance can sit beside the workflow.

Identity lives in Okta. Approval lives in Slack or Jira. Policy lives in a PDF or GRC tool. Evidence lives in the ticket, order, doc, spreadsheet, or data warehouse. Audit events live in logs. The actual business action lives somewhere else: Shopify, Stripe, HubSpot, Meta, a database, an AI tool, or a custom admin panel.

That model becomes fragile when work becomes faster and more automated. A human can sometimes remember why an exception was allowed. A workflow cannot. An AI agent cannot be trusted to infer permission from a Slack thread. A regulator will not accept "the evidence was probably in the old ticket." The proof has to travel with the action.

This is especially important for AI-assisted work. The company may change models, prompts, tools, policies, and vendors many times. The durable part should be the action record: who acted, what was allowed, what evidence was used, what policy applied, and what event was written.

AI makes the gap harder to ignore

On February 14, 2024, the British Columbia Civil Resolution Tribunal ordered Air Canada to pay a customer after its chatbot gave the wrong refund advice. Air Canada argued the chatbot was responsible for its own statement. The tribunal rejected that.

The company was responsible.

In August 2023, iTutorGroup paid $365,000 to settle an EEOC claim that an automated hiring system rejected older applicants. Again, the issue was not just the model. It was the company's ability to explain, prove, and govern what the system did.

The EU AI Act now requires high-risk AI systems to support automatic event recording. The high-risk regime applies from August 2, 2026. The SEC cybersecurity disclosure rule already requires public companies to describe board oversight of cyber risk. ISO/IEC 42001:2023 gives organizations an auditable AI management standard.

The direction is clear: if a system takes action, the company must be able to prove why it was allowed.

What good governance looks like

Good governance does not start with a separate dashboard. It starts with the action record.

If a workflow issues a refund, launches an experiment, changes a price, approves a vendor, exports a customer file, or lets an AI agent send a message, the action should not write unless the required proof is present.

That is the difference between:

  • "We think this was approved because there is a Slack thread."
  • "This action has approval ID X, policy version Y, actor Z, and evidence refs A, B, and C."

The second version is faster to audit, easier to trust, and safer to automate.

What Lyberty does

Lyberty attaches the proof to the work while the work happens.

Approvals, policies, identities, evidence, and audit events are not only compliance objects. They are part of the same execution flow that launches offers, pages, campaigns, experiments, finance actions, and AI-assisted work.

If a Lyberty workflow calls another system through a connector, Lyberty keeps the proof on its side. The downstream vendor's own record is only as strong as that vendor allows. We do not pretend to control every external database. We do make the Lyberty-side action auditable without reconstruction.

What to check

  1. Pick one sensitive action: refund, price change, customer export, model output, budget change, or deployment.
  2. Ask who acted.
  3. Ask what authority allowed it.
  4. Ask which policy version applied.
  5. Ask who approved it or why approval was not required.
  6. Ask what evidence justified it.
  7. Ask where the permanent audit event lives.

If answering those questions requires several tools and a meeting, governance is not attached to the work yet.

Sources

  1. Unauthorized Access to Okta's Support Case Management System. Okta, November 2023. https://sec.okta.com/articles/2023/11/unauthorized-access-oktas-support-case-management-system-root-cause/
  2. Okta: Breach Affected All Customer Support Users. Krebs on Security, November 2023. https://krebsonsecurity.com/2023/11/okta-breach-affected-all-customer-support-users/
  3. Vanta Raises $150M Series C. TechCrunch, July 24, 2024. https://techcrunch.com/2024/07/24/trust-management-platform-vanta-raises-150m-series-c-now-valued-at-2-45b/
  4. Drata's Valuation Rises to $2 Billion. PR Newswire / Drata, December 7, 2022. https://www.prnewswire.com/news-releases/dratas-valuation-rises-to-2-billion-with-200-million-series-c-funding-301696704.html
  5. Okta Closes $6.5 Billion Auth0 Acquisition. Auth0 / Okta, May 3, 2021. https://auth0.com/blog/okta-acquisition-announcement/
  6. Permit.io Raises $8 Million Series A. Business Wire, February 13, 2024. https://www.businesswire.com/news/home/20240213359627/en/Permit.io-Raises-$8-Million-to-Free-Engineers-to-Write-Code-Not-Policies
  7. Regulation (EU) 2024/1689 - Article 12: Record-Keeping. Official Journal of the European Union. https://artificialintelligenceact.eu/article/12/
  8. AI Act Implementation Timeline. European Commission. https://artificialintelligenceact.eu/implementation-timeline/
  9. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST, January 2023. https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
  10. SEC cybersecurity disclosure rule. SEC, July 26, 2023. https://www.sec.gov/newsroom/press-releases/2023-139
  11. ISO/IEC 42001:2023. ISO, December 2023. https://www.iso.org/standard/42001
  12. iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit. EEOC, August 9, 2023. https://www.eeoc.gov/newsroom/itutorgroup-pay-365000-settle-eeoc-discriminatory-hiring-suit
  13. Moffatt v. Air Canada, 2024 BCCRT 149. ABA Business Law Today, February 2024. https://www.americanbar.org/groups/business_law/resources/business-law-today/2024-february/bc-tribunal-confirms-companies-remain-liable-information-provided-ai-chatbot/
  14. Cost of a Data Breach Report 2024. IBM Security, July 2024. https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs
  15. SEC Charges Knight Capital With Violations of Market Access Rule. SEC, October 16, 2013. https://www.sec.gov/newsroom/press-releases/2013-222
  16. SolarWinds / SUNBURST analysis. Google Cloud / Mandiant. https://cloud.google.com/blog/topics/threat-intelligence/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor