What it evaluates
Whether an action taken by an actor exceeded the declared authority limit
for that actor, action type, and context. Each limit is declared by the organisation;
EVE compares the observed action to the declared threshold. Verdict is
breach if exceeded, pass if within,
unknown if the actor, action, or limit cannot be placed
(fail-closed — never treated as pass).
DORA governance area
ICT risk management governance / delegated control ownership.
DORA requires management bodies to define, approve and oversee ICT risk management arrangements and to maintain clear accountability for ICT-related decisions.
The Authority Boundary signal surfaces whether an observed ICT action was within the declared authority of the responsible function.
Art 5 Management body responsibilities
Art 6 ICT risk management framework
Output verdicts
breach
pass
unknown
unknown → actor, action, or limit unresolvable. Never a pass.
Domain proof — sealed on EVE Bridge
EVE-DORA-00004289
breach / authority_limit_exceeded
→ ICT change at impact level 5 above declared authority (limit 3) · Human decision: reject
Verify publicly →
Synthetic DORA demo proof — shows the Authority Boundary mechanism in a DORA context. Not a real DORA finding or enforcement action.