Beyond Cybersecurity: What Emergent Authority Makes Possible

09 Sep 2610 min read

The New Stack recently spent some time with us exploring an idea we have been working on at Tide for years. Their headline got straight to it: “Why authority is the attack surface AI security keeps missing.” Read The New Stack article

That sounds like a cybersecurity problem. It is. Cybersecurity is where the consequences become obvious first, but the implications of Emergent Authority reach much further.

Because if authority itself can be redesigned, something much bigger changes. We can start building systems, businesses and institutions that do not require somebody, somewhere, to hold dangerous amounts of power just to make useful things happen. That opens some interesting doors.

First, what is authority?

Start with a simpler question. What gives a digital system the power to act? That power is authority. It is what lets a server decrypt your information, an administrator enter a production system, an identity provider say you are you, software approve a transaction, an AI agent act on your behalf, or a company decide who can access what.

Today, that authority almost always lives somewhere. There is a key in a vault. A privileged account. A signing secret. A service account. A root administrator. Some person or machine eventually has enough power to make the important thing happen.

Cybersecurity has spent decades trying to protect whoever holds that power. We surround those holders with firewalls, vaults, MFA, monitoring and endless patching, but the basic bargain stays the same. Defenders have to get everything right, while an attacker needs only one useful mistake.

Tide was built to change that underlying architecture, not add another defensive layer around it. With Emergent Authority, consequential authority is not permanently held by a person, server, administrator, vendor or AI. Instead, Tide's decentralized Cybersecurity Fabric distributes the cryptographic capability across independent nodes. When identity, policy, context and intent line up, those nodes collectively perform the permitted action. The complete underlying authority never needs to exist in one place.

We started with a simple way of describing it.

Keys no one will ever hold.

The more important idea hiding underneath is this:

Power can be exercised without somebody possessing the power.

That changes security. It may change quite a lot more.

What Emergent Authority means for developers

Developers have inherited an increasingly ridiculous job. Build quickly. Use hundreds of dependencies. Connect dozens of services. Manage identities, permissions, secrets and infrastructure. Keep everything patched. Configure everything correctly. Make sure no credential leaks. And now, do it while AI produces software faster than anyone can realistically inspect it. Meanwhile, an attacker only has to find one useful mistake.

That imbalance is why we built TideCloak, our Keycloak-compatible Identity, Immunity and Access Management layer. It brings Emergent Authority into familiar OIDC and OAuth application flows without asking developers to become cryptographers. More recently, we built Raziel, Tide's MCP server for AI coding agents, to identify concentrations of authority and guide agents through integrating TideCloak into a developer's project.

But the bigger developer story is not another security tool. It is a different bargain:

  • What if your application could be full of ordinary software bugs, yet those bugs could not reveal the signing key because the signing key was never there?
  • What if compromising your identity server did not automatically grant the attacker the power to forge identities?
  • What if an AI-generated application could interact with sensitive information without the backend becoming another place capable of reading all of it?

This is what we mean by changing the architecture instead of endlessly defending the prize. The developer can get back to building. And that matters because when the cost of safely building something falls, we tend to build a lot more of it.

Security is only the first-order effect

Here is where things get more interesting. The most important consequence of safer cars was not that people worried less about crashing. Cars made mobility practical at enormous scale. That changed where people lived, how businesses operated, what could be transported, where people worked and what they did with their weekends. The safety improvement enabled everything downstream.

Emergent Authority opens the door to a similar second-order effect. The immediate outcome is that dangerous authority becomes harder to steal or misuse. The larger outcome is that we can start to cooperate without first having to trust somebody with dangerous power.

And trust is currently one of the great hidden constraints on what we can do together.

AI could become a real delegate

Consider AI agents. An assistant that tells you how to lower your electricity bill is useful. An agent that can read your private usage data, change providers, negotiate the contract, make the payment and update your accounts is much more useful. But now it needs the authority to perform those actions.

The more useful the agent becomes, the more frightening that becomes too. We do not particularly want a clever piece of software carrying reusable credentials to our identity, finances, company infrastructure and private information.

Emergent Authority creates another possibility. Give the agent the ability to get legitimate work done without giving it permanent possession of the authority behind that work. AI can move from advising people to genuinely working for them, while the infrastructure remains capable of saying what it may do, under which circumstances, and on whose behalf.

That could make sophisticated personal administration available to almost everyone. A person could have software continuously dealing with bills, travel, government paperwork, investments, insurance, subscriptions and business administration. Things wealthy people solve today with assistants, accountants, lawyers and family offices could increasingly become ordinary software capabilities.

Not because AI suddenly became trustworthy. Because trust became less necessary.

Small companies could act much bigger

The same thing happens to businesses. A five-person startup can already rent computing infrastructure that once required a multinational-sized data center. AI is now giving that same small team access to extraordinary cognitive capability. Authority remains one of the bottlenecks.

A major bank can hire a small specialist today, but giving that specialist meaningful access to sensitive systems creates risk. Companies keep work inside organizational boundaries partly because insiders are easier to govern than outsiders. Reduce that risk and the boundaries of the firm can become much more fluid.

A small company could safely assemble AI agents, contractors, specialist suppliers and infrastructure from around the world, giving each exactly the authority needed to contribute without turning each one into another dangerous insider. That means smaller companies can coordinate much larger amounts of capability.

Remote work becomes deeper than video meetings. Global specialists can participate in consequential work without being handed broad access. Tiny teams become viable competitors in industries where security and trust requirements currently favor giant incumbents. The productivity gain could dwarf the security gain.

Valuable data could finally be used

Some of humanity's most valuable information is also information we are least willing to share: medical histories, genomic datasets, financial activity, industrial performance, infrastructure data and scientific research. There are good reasons for that.

A hospital might learn far more about a rare disease by combining information with hundreds of hospitals around the world. But doing so traditionally means somebody has to collect, control or gain access to an extraordinary pool of sensitive information. So much of the potential value remains stranded.

A world where useful operations can occur without one party receiving unilateral authority changes the equation. Hospitals could collaborate without creating a new holder of everyone's medical records. Banks could collectively detect fraud without handing one organization complete visibility into every customer's financial life. Companies could contribute information to shared AI or industry analysis without first surrendering it to another platform.

Privacy then stops being only about preventing something bad. It becomes an enabler of things we currently cannot safely do. More research. Better models. Better medicine. Better collective intelligence.

We could get scale without always creating a ruler

There is an even larger pattern here. Whenever humans want to coordinate something big, we tend to create something powerful to coordinate it:

  • Banks coordinate capital.
  • Platforms coordinate digital markets.
  • Governments coordinate public services.
  • Large companies coordinate thousands of workers.

Someone ultimately controls the infrastructure, the database, the money, the permissions or the keys. Scale tends to create custody, and custody tends to create concentrated power. That is not always bad. Often it is simply the only practical architecture we have had.

Emergent Authority suggests another possibility. What if a group could coordinate a shared resource without appointing one participant as its technical sovereign?

Communities could pool capital around local infrastructure without one person holding the master account. Companies that compete with one another could operate shared systems without one competitor controlling them. Governments that do not entirely trust one another could still cooperate around shared infrastructure because no country has unilateral control. New organizations could appear around a project and disappear when the project is finished, without first constructing an elaborate hierarchy of custodians.

The opportunity is not decentralization for its own sake. It is coordination at scale without custody at scale, an idea The New Stack picked up in its exploration of Tide. That is a much more useful goal.

A lower trust economy could simply do more

Trust is expensive. We rarely see the bill because it is buried across the economy. It appears in audits, insurance, compliance, supervision, escrow, bureaucracy, intermediaries and the countless things organizations choose not to do because the trust assumptions are too dangerous.

It also shapes our institutions. We favor large suppliers because we trust them more than unknown startups. We keep data siloed because sharing it creates liability. We keep humans supervising processes that software could perform because giving software authority feels reckless.

We also wrap critical access in layers of infrastructure because the intermediary itself has to be trusted. Applying Emergent Authority to manage infrastructure access in the form of KeyleSSH shows what changes when that intermediary becomes an oblivious proxy. It can broker remote access without holding the keys or seeing the session, allowing much of the surrounding security infrastructure to disappear with it. The result is not only stronger security, but simpler infrastructure and better performance.

Lower the amount of trust required, and some of those constraints move:

  • More work can cross company boundaries.
  • More capital can form around smaller opportunities.
  • More assets can be shared.
  • More information can become useful.
  • More organizations and individuals can adopt powerful AI with confidence.
  • More strangers can collaborate.
  • More small organizations can compete with large ones.

The important outcome is not a world where nobody trusts anybody. Quite the opposite. It’s a world where cooperation no longer requires making yourself dangerously vulnerable to whoever sits on the other side, or taking on liabilities you never wanted to carry in the first place.

Cybersecurity is where this starts

We built Emergent Authority because cybersecurity has an authority problem. Traditional systems place enormous power inside extractable things, then spend enormous effort protecting those things. A single credential, administrator, signing key or service can become the path through which an otherwise sophisticated system collapses.

Tide's work has been about removing that structural weakness. The authority behind authentication, authorization, decryption and privileged access can be kept beyond the unilateral reach of the systems and people using it. That alone is worth pursuing.

The more we work with the idea, the clearer it becomes that cybersecurity is only where Emergent Authority begins.

Human progress has always depended on better ways to coordinate with people beyond those we personally know and trust. Money helped strangers trade. Contracts helped strangers make commitments. Companies helped strangers pool capital. The internet helped strangers exchange information and build together across the planet.

Perhaps the next step is making it possible for strangers, companies, machines and institutions to cooperate deeply without requiring any of them to hold disproportionate power over the others.

That is the opportunity behind Emergent Authority. A safer internet would be useful. A world capable of coordinating vastly more human and machine capability without concentrating vastly more power is the real opportunity.

News & views