Loading

Break-Glass and Dual Authorisation

Two controls sit above clearance, for cases where "no" is the right default but not an absolute.

Where to find it

Architect Panel → Security:

  • Classification & Clearance — where break-glass is enabled and its events reviewed
  • Dual Authorisation — which actions require two people

Architect Panel → Activity:

  • Record Read Log — who opened what, including every break-glass access

Break-glass

Break-glass lets somebody open a record their clearance would normally refuse, on the explicit understanding that the act is recorded and will be read.

It exists because a rigid control gets circumvented. If an out-of-hours social worker genuinely needs a file and the system says no, they will telephone somebody who says yes, and there will be no record at all — not of the access, not of the reason, not of who authorised it. The information has been disclosed either way; the only question is whether your system knows.

Break-glass keeps that access inside the system where it can be seen. Require a reason at the point of use. A reason typed in the knowledge that a named person will read it is a meaningfully better record than a tickbox, and it is also a mild deterrent to casual curiosity.

Reviewing break-glass

Break-glass without review is just access with extra steps. Give somebody the explicit job of reading the log on a schedule, and keep the volume low enough that reading it is realistic.

A steady stream of break-glass events almost always means the clearance model is wrong rather than that people are misbehaving — the level is set too high, or too few people are cleared. Treat a rising trend as a design signal, not a discipline problem.

Dual authorisation

Dual authorisation requires two people for an action, so no single person can take it alone. Configure which actions require it in Security → Dual Authorisation.

Use it sparingly and where the risk genuinely warrants it:

  • Opening a case involving a colleague or an elected member.
  • Lowering a classification.
  • Disposing of records ahead of schedule.
  • Releasing information externally where the release is itself consequential.
  • Merging two party records that a conflict check flagged.

The second person must be a second person

If the second approver always approves without looking, the control is theatre and everyone involved knows it. Fewer dual-authorisation points that are taken seriously beat many that are rubber-stamped.

Two practical rules make it real: the approver should be someone who could plausibly say no, and the request should carry enough context to make refusing possible. An approval request that says only "approve access?" cannot be assessed.

Worked example — a legal practice

A matter involving a partner's family member is classified Highly Restricted. The three fee earners with clearance can open it normally. Anyone else must break glass, stating why, and the practice manager reads those events weekly. Lowering the classification requires dual authorisation from the supervising partner and the COLP, so the case cannot quietly become ordinary.

Recommendations

  • Tell staff break-glass exists and is reviewed. A control nobody knows about deters nothing and gets bypassed by phone.
  • Set a review cadence and keep it. Weekly is realistic for most; monthly is the most that is still meaningful.
  • Investigate the pattern, not the individual, first. Most break-glass is legitimate work meeting an over-tight control.
  • Never use dual authorisation as a substitute for training. It slows an action down; it does not make the person better at judging it.