Infringement
Abuse of Decision-Making Authority
Codebase Integrity Compromise
Data Integrity Manipulation
Data Loss
Delegated Execution via Artificial Intelligence Agents
Deliberate Safety Control Defeat
Denial of Service
Digital Defacement
Disruption of Business Operations
Excessive Personal Use
Exfiltration via Automated Transcription
Exfiltration via Email
Exfiltration via Media Capture
Exfiltration via Messaging Applications
Exfiltration via Other Network Medium
Exfiltration via Physical Medium
- Exfiltration via Bring Your Own Device (BYOD)
- Exfiltration via Disk Media
- Exfiltration via Floppy Disk
- Exfiltration via New Internal Drive
- Exfiltration via Physical Access to System Drive
- Exfiltration via Physical Documents
- Exfiltration via Target Disk Mode
- Exfiltration via USB Mass Storage Device
- Exfiltration via USB to Mobile Device
- Exfiltration via USB to USB Data Transfer
Exfiltration via Screen Sharing
Exfiltration via SMS/MMS
Exfiltration via Web Service
External Credential Sharing
Harassment and Discrimination
Inappropriate Web Browsing
Installing Malicious Software
Installing Unapproved Software
Internal Credential Sharing
Misappropriation of Funds
- Creation of Fictitious Invoices
- Creation of Fictitious Work Orders
- Excessive Overtime
- Fraudulent Refund Issuance
- Insider Trading
- Manipulation of Performance-Based Compensation
- Misappropriation of Redeemable Value
- Misuse of a Corporate Card
- Modification of Invoices
- Prepaid Debit Cards
- Unauthorized Bank Transfers
Misuse of Corporate Communication Channels
Non-Corporate Device
Organizational Resource Diversion
Physical Sabotage
Providing Access to a Unauthorized Third Party
Public Statements Resulting in Brand Damage
Regulatory Non-Compliance
Sharing on AI Chatbot Platforms
Theft
Unauthorized Account Access
Unauthorized Changes to IT Systems
Unauthorized Organizational Representation
Unauthorized Presence in Restricted Physical Areas
Unauthorized Printing of Documents
Unauthorized VPN Client
Unauthorized Work Location
Undisclosed Concurrent Employment
Unlawfully Accessing Copyrighted Material
- ID: IF044
- Created: 01st August 2026
- Updated: 01st August 2026
- Contributor: The ITM Team
Abuse of Decision-Making Authority
A subject deliberately uses a decision-making authority granted through their organizational role to approve, deny, waive, prioritize, suppress, or otherwise determine an outcome for an unauthorized purpose.
The subject may be technically and procedurally entitled to make the decision. The infringement arises because the authority is exercised contrary to the organization’s interests, applicable policy, delegated limits, or the legitimate purpose for which the authority was granted.
This behavior may be difficult to identify through conventional access-control monitoring because the subject acts through authorized workflows and assigned permissions. Investigation requires examination of the decision, its stated justification, the subject’s relationship to affected parties, applicable policy requirements, and comparable decisions made under similar circumstances.
This is narrower than general “authority abuse.” It focuses on the improper exercise of an entrusted decision right.
Subsections (6)
| ID | Name | Description |
|---|---|---|
| IF044.002 | Improper Denial | A subject uses organizational authority to deny another person a service, benefit, request, opportunity, access right, payment, review, or other outcome without a legitimate organizational basis.
Examples include:
|
| IF044.003 | Improper Preferential Treatment | A subject uses decision-making authority to provide an unauthorized advantage to a person, organization, account, supplier, applicant, or other beneficiary.
Examples include:
|
| IF044.004 | Suppression of Escalation or Review | A subject uses their authority to prevent, terminate, delay, redirect, or improperly narrow a required organizational review, escalation, complaint, referral, or investigation.
Examples include:
|
| IF044.001 | Unauthorized Approval | A subject uses delegated authority to approve a request, transaction, entitlement, exception, appointment, payment, access grant, or other organizational action without a legitimate basis.
Examples include:
The defining evidence is an affirmative decision made through authority legitimately assigned to the subject. |
| IF044.006 | Unauthorized Prioritization or Deprioritization | A subject uses decision-making authority to improperly accelerate, delay, elevate, or deprioritize a request, case, transaction, task, customer, or other item within an organizational process.
Examples include:
|
| IF044.005 | Unauthorized Waiver or Control Exception | A subject improperly waives, bypasses, suspends, or grants an exception to a mandatory organizational control using authority available through their role.
Examples include:
|