Use Case · Continuous Authority Assurance

Know who was authorized. At any moment. Without the quarterly scramble.

Pick any date last quarter. Can you show, without a scramble, who was authorized to approve, sign, and commit on your behalf that day, up to what limit, and that the limit held? Most teams answer only by reconstructing it after the fact, from spreadsheets, inboxes, and memory. Aptly holds every delegation, limit, and condition as a structured, versioned record, so the answer is point-in-time recall, available on demand for any moment in the period.

Aptly recalling who held approval and signatory authority on a chosen past date, with the limit that applied.
Security & compliance
SOC 2 Type II
ISO 27001
GDPR
The Gap

Authority is audited as a point-in-time reconstruction, not assured as it operates.

Most enterprises prove their authority controls the same way every year: they reconstruct them. When the auditor asks who could approve a commitment in a given month, and whether the limit held, the answer is assembled by hand, weeks later, from whatever evidence survived. A control that existed on paper is not the same as a control you can show operated, on every day of the period.

Evidence is rebuilt after the fact, not captured as it happens. The delegation register, the limit that applied, who actually approved, and whether anyone exceeded their authority are pieced together from emails, screenshots, and recollection, long after the decisions were made.

You can show a control exists, not that it operated all year. Auditors and regulators increasingly want evidence the control was effective throughout the reporting period, not just that a policy was in place on the day it was tested. A point-in-time snapshot does not answer a throughout-the-period question.

The scramble repeats every cycle. Each quarter and each audit re-opens the same manual reconstruction, because nothing in between was assured. The effort scales with every entity, system, and framework you answer to.

51%

Third-Party Research

In the ACFE 2024 Report to the Nations (1,921 cases analyzed), more than half of cases involved internal controls that were absent or overridden. That is the failure the authority layer is built to prevent: the limit existed, but no one could show it held.

Survey-based; ACFE, 2024.

The shift is not a faster reconstruction. It is moving authority up a maturity curve, from a static record you rebuild on demand to a control whose state you can recall for any moment in the period.

The Authority Layer

Continuous assurance, applied to the authority layer.

Aptly sits between your identity systems (Okta, Microsoft Entra ID, SailPoint) and your execution systems (SAP, Oracle, NetSuite, Workday, ServiceNow) as the system of record for who can approve, sign, and commit on behalf of the enterprise. Identity governs who can log in; your ERP routes transactions; Aptly governs decision authority, and records it as it changes. Because every delegation, acceptance, re-delegation, limit, condition, and expiry lives in Aptly as a structured, versioned record, you can recall who was authorized at any moment, for any limit, without reconstructing it.

Continuous controls monitoring watches the transaction. Aptly assures the authority behind it. Continuous-controls-monitoring and continuous-auditing tools test the financial-transaction population: journal entries, payments, and postings, scanned for anomalies across the full set of activity. That is valuable, and complementary. Aptly answers the question those tools assume is already settled: who was authorized to make the commitment, within what limit, and was that authority valid at that moment? CCM tells you a payment looked unusual; Aptly tells you whether the person who approved it was actually authorized to, within their delegated limit, at that moment. Use both, with Aptly as the authority layer the transaction monitoring depends on.

Identity systems
Who can log in
OktaMicrosoft Entra IDSailPoint
The Authority Layer
Aptly governs who can approve, sign, and commit
Delegations, limits, conditions, and signatories, versioned and evidenced.
Execution systems
Where transactions happen
SAPOracle · NetSuiteWorkday · ServiceNow
Authority defined once, synced across 30+ identity and execution systems, and recallable for any moment in the period.

Identity proves who you are. Your ERP moves the transaction. Aptly is the system of record for what you are authorized to decide, and the evidence you can recall for any moment in the period.

Maturity Model

Five stages from spreadsheet to continuously assured.

Authority assurance matures along a predictable curve. It mirrors the broader shift across audit and controls, from sampling a portion of transactions toward monitoring the full population, and the rising regulatory demand for evidence that a control operated throughout the reporting period, not just that it existed on the test date. The same shift is described in the COSO Monitoring Activities component (ongoing versus separate evaluations) and the IIA's continuous-auditing guidance. Most enterprises sit at stage two or three. Continuous authority assurance is stage five.

1
Ad hoc
Authority lives in spreadsheets and individual memory, with no central record. Who was authorized on any past date is unknowable without asking around.
2
Documented
A delegation of authority (DOA) policy and matrix exist, but they are static and disconnected from the systems that enforce them. The document ages the day it is saved.
3
Integrated
Available
Approved authority is synced to the ERPs, apps, and identity systems that enforce it, so what is enforced reflects what was approved.
Structured, versioned authority synced across 30+ systems.
4
Monitored
In Preview
Divergence between approved and enforced authority, and exceptions as they occur, are flagged continuously rather than discovered at audit.
The always-on flagging intelligence is in preview; the structured record, real-time sync, and audit trail that make it possible are available today.
5
Continuously assured
Available
Real-time, audit-ready evidence of who was authorized at any moment, with the limit and conditions that applied, recallable on demand for any date in the period.
Point-in-time recall is available today; the always-on layer that makes assurance fully hands-off is in preview.

The shift from stage two to stage five is the shift from rebuilding the answer each quarter to recalling it for any moment, on demand.

The Platform

The platform behind continuous assurance.

Delegation of Authority
Available
Hold every delegation, limit, condition, and acceptance as a structured, versioned record, so who was authorized on any past date is point-in-time recall, not reconstruction.
Learn more →
Signatory Management
Available
Recall who was an authorized signatory for any contract on any date, with validated signatory lists kept in sync with the delegations behind them.
Learn more →
Authority Hub
Available
See authority across every connected system from one dashboard, kept in sync with approved policy across 30+ ERP, HRIS, and identity systems, with immutable action and audit logs that evidence the control as it operates.
Learn more →
Intelligence
In Preview
Navigate the live authority picture and get instant answers on who can decide what today, so assurance teams can spot-check authority on demand instead of reconstructing it at quarter-end.
Learn more →
See point-in-time recall run against a date from your last quarter.
Book a Discovery Call
Frameworks

Regulators want evidence the control operated all year, not just on the test date.

The common thread across these regimes is the one continuous authority assurance is built for: evidence that a control was effective throughout the reporting period. It is the principle COSO names in its Monitoring Activities component and the IIA names in its continuous-auditing guidance. Aptly maps your continuously captured authority evidence to the frameworks that ask for it.

SOX

Prove the control operated all year, not just that it existed.

Section 404 requires evidence the control operated, not just that it existed. Audit practice is moving from point-in-time sampling toward continuous, full-population monitoring of control activity, and authorization limits and segregation of duties are core ICFR controls.
PCAOB AS 2201 and AS 2101 amendments apply to audits of fiscal years beginning on or after 15 Dec 2026; SEC-approved Aug 2025.
UK Code P29

Show material controls operated throughout the year.

Boards must declare whether material controls were effective and describe how the framework was monitored across the year, including authorization and approval controls. The challenge is demonstrating the control actually operated throughout the reporting period, not just on one date.
Applies to financial years beginning on or after 1 Jan 2026; comply-or-explain; no external-auditor attestation. Now in its first declaration cycle.
APRA CPS 230

Show controls are designed and operating effectively.

Operational-risk controls, including approval and authorization controls, must be designed and operating effectively, with effective monitoring and remediation, not a once-a-year check.
Commenced 1 Jul 2025; final targeted amendments released Apr 2026, commencing 1 Jul 2026; subject to change.

You map authority once. Each regime reads the same evidence in its own language, so a new framework becomes a mapping exercise, not another year of reconstruction.

Proof

What point-in-time recall replaces.

Meridian Industries' internal audit lead is preparing for the annual controls review. In prior years this meant weeks of reconstruction: pulling the authority matrix as it stood mid-year, matching it against who actually approved, and proving the limit was enforced in SAP, all assembled by hand. This year the question is the same, but the answer is recall, not reconstruction.

“Show us who was authorized to approve capital commitments above $1M as of 30 June, the limit that applied, and that SAP enforced it.”
Authority as it stood on 30 June
The versioned matrix recalled for the exact date, not today's view.
Who was authorized, and who acted
Every delegation and acceptance for the period, with actor and timestamp.
Enforced, not just intended
The synced limit, proven in SAP for the date in question.

One recall, not a quarter of reconstruction. The same source answered the signatory question for the period. No war room. No screenshots. No surprises.

Illustrative scenario based on Aptly's canonical Meridian Industries dataset. Not a real customer.
FAQ

Questions Internal Audit and controls teams ask.

What is continuous controls monitoring, and how is Aptly different?
Continuous controls monitoring (CCM) watches transactions for anomalies across the full population: journal entries, payments, postings. Aptly assures the authority behind those transactions: who was authorized to approve or commit, within what limit, and whether that authority was valid at the time. CCM flags an unusual payment; Aptly shows whether the person who approved it was actually authorized to. They are complementary, with Aptly as the authority layer CCM depends on.
What does continuous authority assurance actually mean?
It means the state of your authority controls is captured continuously as authority is defined, delegated, synced, and exercised, rather than reconstructed at audit. You can recall who was authorized at any moment, with the limit and conditions that applied, on demand for any date in the period.
How does Aptly prove a control operated all year, not just on the test date?
Every delegation, acceptance, re-delegation, limit, condition, and expiry is recorded with actor and timestamp as it happens. That continuous record lets you show the authorization control was effective throughout the reporting period, the throughout-the-period evidence frameworks increasingly ask for, rather than a single snapshot.
What is the difference between point-in-time recall and continuous monitoring?
Point-in-time recall, available today, lets you reconstruct the exact authority state for any past date instantly. Always-on drift monitoring, which flags divergence between approved and enforced authority as it occurs, is in preview. The structured record, real-time sync, and audit trail that make both possible are available today.
Can Aptly show who was authorized on a specific past date?
Yes. Because authority is held as a structured, versioned record, Aptly can recall who held a given authority, up to what limit, under what conditions, on any specified date, without reconstructing it from emails and spreadsheets.
Pairs With

Built to work with the rest of your authority program.

Use case

Regulatory Readiness & Compliance
Pass audit and prove control across every framework you answer to.

View use case →

Use case

Approval Matrix Management
Keep authorization limits synced to every ERP and app, every day.

View use case →

See where your authority assurance sits, and what continuous looks like.

Bring a date from your last quarter. We'll show you who Aptly says was authorized that day, the limit that applied, and how point-in-time recall replaces the reconstruction. Then we'll map it to the framework you answer to.