Offers

Dual control that survives Tuesday

Dual control that only exists in a policy PDF fails on a busy Tuesday. Production dual control is enforced, staffed, and evidenced.

By FazeZero Editorial Team 2 min read

Part of Product Offers (3)

Most “dual control” is a slide.

It dies when:

  • Shared admin is still on.
  • The maker and checker are the same person after hours.
  • The tool allows a bypass that nobody logs.
  • The ticket closed without the evidence primary key.

Tuesday is the test. Volume is up. Someone is on leave. The corridor is hot. Policy PDFs do not move.

Production dual control has four parts

  1. Policy that the system can enforce (or a manual gate that is actually staffed).
  2. Segregation that survives staffing gaps — named roles, not heroics.
  3. Exception path with a register, not a private chat.
  4. Evidence that the dual control event happened — linked to the ticket.

If any one of those is missing, you have theatre.

What a sprint does

We do not sell a new custody product. We design dual control on the stack you already run (or have contracted), map the as-is failures, and leave a to-be model plus control matrix for one workflow.

Wiring configuration often follows as Integration SI — after the design is accepted, or via a vendor who is stuck on implementation.

Red flags in a fit call

  • “We have dual control” but cannot show last week’s maker/checker record.
  • Owner keys discussed as something we would hold. (We will not.)
  • Request to “make the tool compliant” without naming the workflow.

Offers · How we work

Next step: If dual control fails on a real book this month, say so on the fit call. That is a production problem, not a branding problem.

Fence: We configure guidance on client-owned systems. No owner/root admin. No keys.