A rule cannot be trusted without a defensible chain of authority

Rules govern because some source gives them force. That source may be a constitution, statute, regulation, judicial order, contract, corporate charter, board resolution, delegated office, professional standard, or recognized institutional process. The authority of a rule is therefore not contained in its wording alone.

Hierarchy organizes those sources. It identifies which rules are superior, subordinate, implementing, specialized, temporary, or merely advisory. Delegation explains how authority moves from one level to another. Precedence determines which rule controls when multiple rules appear to govern the same case.

This chapter examines authority as a structural property of rule systems. It explains how institutions should identify sources, record delegation, distinguish stricter policy from contradiction, recognize unauthorized rules, resolve conflicts, and control authority embedded in technical systems.

Authority gives a rule force; hierarchy organizes that force

Working definition: Rule authority is the legitimate power or accepted basis by which a rule is created, imposed, recognized, or enforced. Rule hierarchy is the structured ordering of rule sources and rule expressions according to their legal, contractual, organizational, or technical priority.

Authority answers the question: Why may this rule govern? Hierarchy answers: How does this rule relate to other rules that may also govern?

The distinction matters because a rule can possess authority without being superior to every other rule. A departmental procedure may be valid within its delegated field while remaining subordinate to enterprise policy, contract, and law. A contract may bind its parties while remaining subject to mandatory law. A technical access rule may be enforceable in software while lacking organizational authority to alter the underlying policy.

Authority is therefore both a source question and a boundary question. The source must be legitimate, and the rule must remain within the subject, population, jurisdiction, process, and procedure that source authorizes.

Different rule systems derive authority from different institutions

The source of authority determines the kind of obligation created, the actors governed, the procedure for adoption, and the mechanisms for review or challenge.

Public law

Constitutions, statutes, and regulations

Authority arises through public institutions and legally prescribed processes.

Adjudication

Judicial and administrative orders

Authority may arise from a tribunal empowered to interpret, command, or resolve disputes.

Agreement

Contracts and negotiated commitments

Authority arises from consent, lawful exchange, and enforceable relationship.

Institution

Charters, boards, policies, and delegations

Authority arises from organizational governance and assigned decision rights.

Profession

Standards, codes, and accepted practice

Authority may arise through licensing, accreditation, contract, incorporation, or recognized professional duty.

Technology

System configuration and automated controls

Authority may be operationally effective, but must still be traceable to a legitimate human or institutional source.

These sources are not equivalent. A professional standard does not automatically have the force of law. A policy does not automatically amend a contract. A software configuration does not automatically create a valid organizational prohibition. Rules Integrity requires institutions to identify the precise mechanism by which a source becomes governing.

Hierarchy is a relationship of authority, implementation, and control

Rule hierarchy is often represented as a pyramid, but real rule systems are more complex. Several hierarchies may coexist: legal hierarchy, contractual hierarchy, corporate governance hierarchy, policy hierarchy, document hierarchy, and technical implementation hierarchy.

An illustrative rule hierarchy

A lower layer may contain greater detail, but not greater authority. The detailed procedure explains how a higher rule will be carried out. It should not silently reverse, narrow, or expand the higher rule unless delegated discretion permits it.

Hierarchy also creates responsibility. Higher-level rules should establish purpose, authority, and governing boundaries. Lower-level rules should preserve those elements while translating them into operational decisions.

Delegation transfers decision power within defined limits

Institutions cannot make every decision at the highest level. Authority must be delegated to offices, roles, committees, business units, professionals, and systems. Delegation allows scale, but it also creates risk if scope and limits are unclear.

A complete delegation should identify:

  • the delegating authority;
  • the receiving role or body;
  • the subject matter delegated;
  • financial, geographic, temporal, or risk limits;
  • conditions requiring consultation or escalation;
  • whether redelegation is permitted;
  • documentation and reporting duties;
  • revocation, expiration, and succession.

Delegation does not necessarily remove responsibility from the delegating authority. Oversight, monitoring, and review may remain required. Nor does the ability to act imply authority to create permanent rules. A manager may decide individual cases without possessing authority to establish a policy for the entire organization.

In public law, delegation is constrained by enabling authority and administrative procedure. In private institutions, delegation is constrained by charter, governance documents, contract, law, and internal approval structure.

When several rules apply, priority must be determined rather than assumed

Precedence identifies which rule controls when multiple rules point toward different outcomes. Priority may arise from superior authority, narrower scope, later adoption, express override, emergency status, or another recognized rule of interpretation.

Common priority principles include:

  • superior authority controls subordinate authority;
  • a specific rule may control a general rule within the specific subject;
  • a later rule may displace an earlier rule of equal authority;
  • mandatory law may override contract or internal policy;
  • an express exception may control the general rule;
  • a temporary emergency rule may suspend ordinary operation within defined limits.

These principles are not universal algorithms. Their use depends on the rule system. A later policy cannot override an older statute. A specific local rule cannot displace a superior enterprise rule unless local variation is authorized. Priority must be supported by the authority structure, not merely by preference for the rule that is newer, stricter, or more detailed.

Specificity can determine application without changing authority

A general rule establishes an expectation across a broad field. A specific rule addresses a narrower category or condition. Where both apply, the specific rule may control because it was designed for the exact circumstance.

For example, an enterprise rule may require all vendor contracts to undergo review. A more specific rule may permit standard low-risk renewals to proceed through an automated review path. The specific rule does not necessarily contradict the general rule; it may define how the general requirement is satisfied for a narrower class.

Specificity should be explicit. The narrower rule should identify the general rule, the governed category, the reason for different treatment, and whether the specific rule supplements, implements, or overrides the general one.

Chronology matters only within a valid authority relationship

Later rules may replace earlier rules when they arise from the same or superior authority and address the same subject. But chronology alone does not establish superiority.

Change control should distinguish:

  • express repeal or replacement;
  • partial amendment;
  • temporary suspension;
  • implicit displacement through irreconcilable later requirements;
  • continued historical applicability to prior events;
  • parallel versions for different jurisdictions or populations.

The safest rule system avoids relying on implicit displacement. It should record exactly which provision is superseded, which remains in force, and how historical decisions are treated.

External material becomes governing only through a valid adoption mechanism

Institutions often rely on standards, schedules, codes, guidelines, or external documents. A rule may incorporate that material by reference rather than reproduce it. The incorporation mechanism determines whether the external material is mandatory, advisory, current, or frozen to a particular version.

The U.S. Office of the Federal Register maintains formal procedures for incorporation by reference in federal regulations, including approval, identification, and availability requirements.4 Although internal organizations are not always subject to that legal process, the integrity principles remain useful.

A valid incorporation record should identify:

  • the exact title, issuer, version, and date;
  • the adopting authority;
  • whether future revisions are automatically adopted;
  • where the material is accessible;
  • which portions are incorporated;
  • how conflicts with internal rules are resolved.

A stricter rule may be legitimate, but stricter does not automatically mean superior

Organizations often adopt internal rules more restrictive than the minimum required by law or contract. This may reflect risk tolerance, ethics, safety, quality, or strategic choice.

A stricter internal rule is legitimate when:

  • the organization possesses authority over the governed actor or process;
  • the stricter requirement does not violate a right, permission, or mandatory obligation;
  • the burden is proportionate and feasible;
  • the stricter position is intentional and documented;
  • the rule is not misrepresented as an external legal requirement;
  • exceptions and local constraints are addressed.

A threshold stricter than law is not necessarily a contradiction. It may be a deliberate control. But if the stricter rule prevents conduct that superior authority affirmatively requires or protects, it may be invalid.

A rule is defective when its issuer acts beyond the granted power

Excess authority occurs when a rule addresses a subject, population, consequence, or jurisdiction outside the issuer's legitimate power. The defect may be obvious, such as a local manager changing enterprise compensation policy, or subtle, such as a technical team creating permanent access restrictions without policy approval.

Indicators include:

  • no identifiable source of authority;
  • authority limited to individual decisions but used to create general policy;
  • authority over process used to alter substantive rights;
  • authority over one entity applied to another;
  • delegation expired, revoked, or never permitted to be redelegated;
  • required approval, consultation, or publication omitted;
  • sanctions imposed beyond authorized consequence.

Rules Integrity requires institutions to distinguish between a rule that is poorly designed and one that is unauthorized. The remedy differs. Poor design may be corrected by revision. Lack of authority requires lawful adoption, withdrawal, or escalation to the proper source.

A rule may influence behavior while lacking valid authority

Organizations often contain informal rules that are widely followed because a senior person expects them, a system enforces them, or employees believe noncompliance will be punished. Operational effect does not prove validity.

A rule may be invalid because:

  • the issuer lacked authority;
  • the rule conflicts with superior authority;
  • required procedure was not followed;
  • the rule expired or was superseded;
  • the governed population was never lawfully included;
  • the rule was materially altered during implementation;
  • the rule depends on inaccessible or unidentified incorporated material.

Invalid rules should not simply remain in place with a warning label. Their operational effects must be identified, affected decisions reviewed where necessary, and implementations corrected.

Modern institutions often divide authority across several actors

Authority is not always centralized. A board may set policy, management may define standards, Legal may interpret external obligations, Risk may establish thresholds, Operations may design procedures, and Technology may implement controls.

Distributed authority requires explicit decision rights:

  • who owns purpose and policy;
  • who interprets law and contract;
  • who sets operational thresholds;
  • who approves exceptions;
  • who may implement or change technical controls;
  • who resolves disagreement;
  • who owns final accountability.

Shared responsibility should not become ambiguous responsibility. A rule system should record which role is authoritative for each kind of decision.

Systems exercise practical power that must remain subordinate to legitimate rule authority

Software can deny access, reject transactions, calculate eligibility, escalate cases, or impose deadlines. These actions have rule-like effect. Yet technical enforcement must be distinguished from authority to create the governing rule.

Technical authority should be controlled through:

  • traceability to an approved rule or decision;
  • defined authority to configure or change the system;
  • segregation of policy ownership and implementation privileges;
  • versioned deployment and rollback;
  • testing against approved semantics;
  • exception and override governance;
  • monitoring for divergence between policy and implementation.

A technically enforced rule may be stricter than the approved policy because the system cannot represent discretion. That difference should be treated as a governed implementation decision, not hidden as an inevitable technical limitation.

Authority conflicts should be resolved through method, not convenience

When two rules conflict, institutions often select the stricter rule or the rule preferred by the most powerful stakeholder. Neither method is reliable.

A structured authority-conflict analysis
01Confirm genuine conflict

Do the rules actually require incompatible outcomes in the same case?

02Identify sources

What authority created each rule?

03Compare scope

Are both rules governing the same actor, subject, time, and jurisdiction?

04Apply priority

Does superiority, specificity, chronology, or express override control?

05Assess reconciliation

Can both rules be satisfied through a lawful interpretation or alternative path?

06Record resolution

Preserve reasoning, authority, affected rules, and implementation changes.

Some conflicts cannot be resolved administratively. They may require legal interpretation, contract amendment, policy approval, judicial review, regulator engagement, or withdrawal of the lower rule.

Authority must be governed throughout the lifecycle

Authority governance includes more than approving new rules. It should ensure that every rule remains connected to a valid source, current delegation, defined owner, and appropriate level in the hierarchy.

Governance responsibilities include:

  • maintaining authority maps and delegation records;
  • reviewing rules for excess authority;
  • controlling incorporation of external material;
  • monitoring expiration and supersession;
  • resolving priority disputes;
  • reviewing technical controls for policy alignment;
  • preserving historical authority for past decisions;
  • ensuring that unauthorized rules are removed or lawfully adopted.

Authority defects can make otherwise clear rules unreliable

Failure case 1

The procedure that changes the policy

A local procedure adds a prohibition that the enterprise policy did not authorize. Employees treat the procedure as binding because it is operationally detailed.

Failure case 2

The expired delegation

A temporary executive delegation ends, but approvals continue under the old authority because the workflow was never updated.

Failure case 3

The stricter rule misrepresented as law

An internal risk threshold is described as a legal requirement, preventing informed review of whether the additional restriction remains justified.

Failure case 4

The incorporated standard with no version

A policy requires compliance with an external standard but does not identify the edition. Later revisions silently change the institution's obligations.

Failure case 5

The system rule with no policy source

Software rejects certain transactions, but no approved rule can be found. The technical control has become the de facto authority.

Failure case 6

The local rule that conflicts with contract

A department adopts a retention period shorter than a customer agreement requires. The lower rule is clear, but compliance would breach the contract.

Twenty questions for authority integrity

  1. 01

    Source

    What precise instrument or decision gives the rule authority?

  2. 02

    Issuer

    Who created or approved the rule?

  3. 03

    Subject authority

    Did the issuer possess authority over this subject matter?

  4. 04

    Population authority

    Did the issuer possess authority over the governed actors or entities?

  5. 05

    Procedure

    Were required approval, consultation, notice, publication, or adoption steps followed?

  6. 06

    Delegation

    Is delegated authority documented, current, and within limits?

  7. 07

    Redelegation

    Was the recipient authorized to transfer the power further?

  8. 08

    Hierarchy

    Where does the rule sit relative to law, contract, policy, procedure, and implementation?

  9. 09

    Superior rules

    Does any higher authority limit or displace the rule?

  10. 10

    Specificity

    Is the rule general, specific, implementing, or exceptional?

  11. 11

    Chronology

    Was the rule amended, suspended, superseded, or replaced?

  12. 12

    Incorporation

    Are external materials precisely identified, available, and validly adopted?

  13. 13

    Stricter position

    Is a stricter internal rule intentional, authorized, proportionate, and accurately described?

  14. 14

    Excess authority

    Does the rule regulate beyond the issuer's power?

  15. 15

    Technical implementation

    Does any system rule exceed or alter approved authority?

  16. 16

    Priority

    Is there a documented method for resolving overlap or conflict?

  17. 17

    Ownership

    Who is authorized to interpret, amend, suspend, and retire the rule?

  18. 18

    Historical validity

    Can the institution reconstruct which authority governed a past decision?

  19. 19

    Challenge

    Is there a process for questioning or appealing unauthorized application?

  20. 20

    Evidence

    Can the full chain from source authority to operational enforcement be demonstrated?

Tracing authority before enforcing the rule

Observed rule

“All exceptions require approval from the Chief Risk Officer.”

Authority questions

  • Which policy granted this authority?
  • Does it cover every rule or only risk policies?
  • May the authority be delegated?
  • Does law or contract reserve some exceptions elsewhere?
  • What happens during vacancy or emergency?

Controlled authority model

Exception authority is mapped by rule family, subject matter, risk level, delegated role, duration, review obligation, and superior legal or contractual constraint.

Stricter internal threshold

Law requires review above $100,000; company policy requires review at $50,000.

Authority analysis

The internal rule is not automatically contradictory. Confirm organizational authority, feasibility, purpose, and that no superior rule affirmatively protects the lower threshold from restriction.

Technical control

A system blocks access for contractors even though policy permits approved contractor access.

Authority analysis

The technical control is stricter than the approved rule. Determine whether the restriction was separately authorized, is a temporary compensating control, or is an unauthorized implementation defect.

Authority is the structural foundation of legitimate rule systems

A rule gains force from a legitimate source acting within defined limits. Hierarchy organizes the relationship among those sources. Delegation transfers decision power. Precedence resolves overlap. Governance preserves the chain from foundational authority to operational implementation.

Without that chain, institutions accumulate rules that are detailed but unauthorized, enforceable but invalid, stricter but unjustified, or technically effective but detached from policy.

Rules Integrity therefore requires authority to be visible, bounded, traceable, and reviewable. The institution should be able to explain who may create the rule, why, within what limits, at what level, and with what relationship to every superior and subordinate rule.

Foundational principle: No rule should be treated as legitimate merely because it is written, enforced, or widely followed. Its authority must be traceable to a valid source, exercised within scope, and preserved through every level of implementation.

Sources informing this chapter

  1. Cornell Law School, Legal Information Institute. Supremacy Clause. Background on constitutional priority within the United States legal system.
  2. Cornell Law School, Legal Information Institute. Delegation. General legal background on transfer of authority and responsibility.
  3. Stanford Encyclopedia of Philosophy. Authority. Philosophical analysis of legitimate authority and reasons for compliance.
  4. U.S. Office of the Federal Register. Incorporation by Reference Handbook.
  5. U.S. Office of the Federal Register. Regulatory Drafting Guide. Guidance on authority citations, scope, amendments, and regulatory structure.
  6. Organisation for Economic Co-operation and Development. Recommendation of the Council on Regulatory Policy and Governance.
  7. OASIS Open. LegalRuleML Core Specification Version 1.0. Formal representation of authority, jurisdiction, temporal attributes, and legal rule relationships.

These sources provide established perspectives on legal authority, delegation, hierarchy, incorporation, regulatory governance, and formal representation. This chapter generalizes those principles across public, contractual, organizational, professional, and technical rule systems.