Loading

Break-Glass and Dual Authorisation

Two controls sit above clearance, for the cases where "no" is the right default but not an absolute.

Where to find it

These features have no dedicated Architect Panel section of their own. They are configured through their datastores, opened from All Datastores, and most of what a caseworker sees appears on the record itself rather than on an admin screen.

Break-glass

Break-glass lets someone open a record their clearance would normally refuse, on the understanding that the act is recorded and will be looked at. It exists because a rigid control gets circumvented: if an out-of-hours worker genuinely needs a file and the system says no, they will phone somebody who says yes, and there will be no record at all.

Break-glass keeps the access inside the system where it can be seen. Require a reason at the point of use — a reason typed under the knowledge it will be read is a meaningfully better record than a tick.

Reviewing it

Break-glass without review is just access. Give somebody the job of reading the log on a schedule, and make the volume small enough that reading it is realistic. A steady stream of break-glass events usually means the clearance model is wrong rather than that people are misbehaving.

Dual authorisation

Dual authorisation requires two people for an action, so no single person can take it alone. Use it sparingly and where the risk genuinely warrants it — opening a case involving a colleague, disposing of a record, releasing information externally.

The two people must genuinely be two people. If the second approver always approves without looking, the control is theatre. Fewer dual-authorisation points that are taken seriously beat many that are rubber-stamped.