CONTROLS & FOUR-EYES
Approval workflows: mandates, RBAC and four-eyes controls
No single pair of hands moves money alone. Client-side signatory mandates put the first set of eyes on every instruction; back-office approval puts the second where policy requires it; and role-based access keeps everyone, client and staff, inside their lane, with every action carrying a name.
Multi-signatory mandates with configurable rules
The first control lives with the client: multi-signatory mandates define who may initiate and who must approve, with configurable approval rules per client. A director drafts, a CFO signs; two signatures for the big ones, one for the routine, the client’s governance, expressed in the product. Signing works in the web app and the native mobile apps, so a required signature is never stuck behind an office door.
The signature in the user’s hand is the Secure Payment Confirmation PIN, SMS-verified setup, per-signer status, safe failure modes.
Back-office approval where policy requires it
The second set of eyes belongs to the institution. Payments route to back-office approval when your policy says they should, by screening outcome, by limit, by client, and land in queues where operations reviews, approves, amends or investigates, with intervention possible on payments in flight. Maker-checker is not a checkbox here; it is how the payment lifecycle is built.
RBAC and segregation of duties across two domains
Client access and back-office access live in separate domains, a structural wall, not a permission setting. Inside each, role-based access control gates what a person sees and does: operations, finance, compliance and support each work within their role, clients within their mandates, and every action on either side is attributable in the audit trail.
Pricing and routing changes, separately audited
Money movement is not the only thing worth two pairs of eyes. Changes to price lists and to money routing, the commercially sensitive levers, carry their own separate audit on top of the platform’s general history: who changed what, when, with validity periods on pricing making every historical charge reconstructible. The controls that govern payments also govern the settings that shape them.
Four-eyes controls FAQ
What does four-eyes mean in practice here?
How flexible are signatory mandates?
When does a payment need back-office approval?
How is segregation of duties enforced?
Are configuration changes controlled too?
Can an administrator bypass the controls?
Watch four eyes land on one payment
A mandate signature, a policy hold, a back-office approval, the trail behind all three, the control loop, live.