A market data board of green and pink price figures
Industries

Financial services

Cash handling areas and secure rooms are allowed to wait for corroboration. Any reduction of a control needs two people. Unsigned revocations open nothing.

Interlocked zonesDual controlImmutable decision logCounterparty attestation

In a cash cage, a false accept is far more expensive than a queue. The policy should be allowed to say so.

InterlockThe second door holds until the composite score clears
Two peopleRequired to lower any control below the tenant floor
ImmutableEvery denial, hold, and revocation is a permanent event
No spreadsheetsCounterparty verification through signed attestation
01

Some rooms are allowed to be slow.

Throughput is the right optimisation for a lobby and the wrong one for a vault anteroom.

Sensitive zones are configured to interlock: the outer door closes and the inner door holds until both modalities have corroborated the credential claim. That is a deliberate decision to spend seconds in exchange for eliminating a class of error, made per room.

Desktop policy follows the same logic. Reaching a privileged jump host can require physical presence in a specific zone, which a laptop on a home network cannot satisfy and does not pretend to. At elevated threat classes, platform hardening can become a precondition of unlock rather than a recommendation in a standards document.

Any change that reduces a control requires two distinct administrators to approve the same compiled policy, and records both identities against the artifact. The interesting insider threat here is not somebody forcing a door; it is somebody quietly lowering a threshold.

Control posture
Cash handling areas
Full interlock
Secure rooms
Full interlock, with tailgate holds enforced
Trading and general floors
Credential plus asynchronous corroboration
Privileged desktops
Physical presence in a named zone required
Elevated threat
Platform hardening as a precondition of unlock
Any control reduction
Two distinct administrators
Incident footage
Off by default, human gate, legal hold only
Decision log
Immutable, with the policy revision on every entry
02

What an examiner can be shown.

Each of these is a queryable record rather than a description of intent.

QuestionEvidence available
Who could enter this room last quarter Decision log filtered by zone, with the matched rule and policy revision on every entry
What were the rules at the time The compiled policy artifact, content-hashed, with named approvers and compile timestamp
Who weakened a control, and who approved it The dual-control record on that compile, naming both administrators
When did this leaver actually lose access The epoch increment, its fan-out, and the resulting denials at each portal
Was this person's device ever unaccounted for Asset lifecycle events, including reported loss and the epoch it triggered
Did anybody bypass the approval chain Gate pass records are sequential and immutable, so a missing signature is visible
03

Two controls that are usually informal.

Counterparty verification

Confirming that somebody works where they claim is normally a letter on letterhead or a spreadsheet of staff names shared between institutions.

A signed attestation answers only the question asked, is verifiable against a published key set, and stops being true the moment the employment does. It cannot be reconstructed into a staff list.

Incident footage

Continuous recording creates a liability that grows every day and answers questions nobody asked. It is not a product feature here.

Footage is retained only on a hold, only after a human authorises it, and only as an encrypted clip. Templates and frames never leave the site regardless.

Dual control is only real if two people are actually involved.

The system requires two distinct administrators to approve any reduction in a control, and records both. It cannot detect one person holding two sets of credentials. That gap is organisational rather than technical, and it is worth naming because it is the most common way this particular safeguard gets hollowed out.

05

Non-negotiables.

Floor enforcement

The compiler refuses a silent drop to credential-only.

Presentation attacks

A strong spoof signal is a hard hold, not a logged warning.

Lost credential

Increments the device epoch without disturbing other access.

Unsigned messages

A revocation without a valid signature is dropped, never retried.

Templates stay local

Nothing biometric leaves the site, including to us.

Every hold is evidence

Denials and holds are immutable events with full context.

Bring the door onto the same epoch as the laptop.

We will walk you through a live portal, a compiled policy pack, and a revocation that closes the turnstile and locks the screen while you watch.