Financial services
Cash handling areas and secure rooms are allowed to wait for corroboration. Any reduction of a control needs two people. Unsigned revocations open nothing.
In a cash cage, a false accept is far more expensive than a queue. The policy should be allowed to say so.
Some rooms are allowed to be slow.
Throughput is the right optimisation for a lobby and the wrong one for a vault anteroom.
Sensitive zones are configured to interlock: the outer door closes and the inner door holds until both modalities have corroborated the credential claim. That is a deliberate decision to spend seconds in exchange for eliminating a class of error, made per room.
Desktop policy follows the same logic. Reaching a privileged jump host can require physical presence in a specific zone, which a laptop on a home network cannot satisfy and does not pretend to. At elevated threat classes, platform hardening can become a precondition of unlock rather than a recommendation in a standards document.
Any change that reduces a control requires two distinct administrators to approve the same compiled policy, and records both identities against the artifact. The interesting insider threat here is not somebody forcing a door; it is somebody quietly lowering a threshold.
- Cash handling areas
- Full interlock
- Secure rooms
- Full interlock, with tailgate holds enforced
- Trading and general floors
- Credential plus asynchronous corroboration
- Privileged desktops
- Physical presence in a named zone required
- Elevated threat
- Platform hardening as a precondition of unlock
- Any control reduction
- Two distinct administrators
- Incident footage
- Off by default, human gate, legal hold only
- Decision log
- Immutable, with the policy revision on every entry
What an examiner can be shown.
Each of these is a queryable record rather than a description of intent.
| Question | Evidence available |
|---|---|
| Who could enter this room last quarter | Decision log filtered by zone, with the matched rule and policy revision on every entry |
| What were the rules at the time | The compiled policy artifact, content-hashed, with named approvers and compile timestamp |
| Who weakened a control, and who approved it | The dual-control record on that compile, naming both administrators |
| When did this leaver actually lose access | The epoch increment, its fan-out, and the resulting denials at each portal |
| Was this person's device ever unaccounted for | Asset lifecycle events, including reported loss and the epoch it triggered |
| Did anybody bypass the approval chain | Gate pass records are sequential and immutable, so a missing signature is visible |
Two controls that are usually informal.
Counterparty verification
Confirming that somebody works where they claim is normally a letter on letterhead or a spreadsheet of staff names shared between institutions.
A signed attestation answers only the question asked, is verifiable against a published key set, and stops being true the moment the employment does. It cannot be reconstructed into a staff list.
Incident footage
Continuous recording creates a liability that grows every day and answers questions nobody asked. It is not a product feature here.
Footage is retained only on a hold, only after a human authorises it, and only as an encrypted clip. Templates and frames never leave the site regardless.
The system requires two distinct administrators to approve any reduction in a control, and records both. It cannot detect one person holding two sets of credentials. That gap is organisational rather than technical, and it is worth naming because it is the most common way this particular safeguard gets hollowed out.
Non-negotiables.
Floor enforcement
The compiler refuses a silent drop to credential-only.
Presentation attacks
A strong spoof signal is a hard hold, not a logged warning.
Lost credential
Increments the device epoch without disturbing other access.
Unsigned messages
A revocation without a valid signature is dropped, never retried.
Templates stay local
Nothing biometric leaves the site, including to us.
Every hold is evidence
Denials and holds are immutable events with full context.
The same control plane. A different floor.
Bring the door onto the same epoch as the laptop.
We will walk you through a live portal, a compiled policy pack, and a revocation that closes the turnstile and locks the screen while you watch.