CONTROLS & FOUR-EYES

Approval workflows: mandates, RBAC and four-eyes controls

No single pair of hands moves money alone. Client-side signatory mandates put the first set of eyes on every instruction; back-office approval puts the second where policy requires it; and role-based access keeps everyone, client and staff, inside their lane, with every action carrying a name.

Multi-signatory mandates with configurable rules

The first control lives with the client: multi-signatory mandates define who may initiate and who must approve, with configurable approval rules per client. A director drafts, a CFO signs; two signatures for the big ones, one for the routine, the client’s governance, expressed in the product. Signing works in the web app and the native mobile apps, so a required signature is never stuck behind an office door.

The signature in the user’s hand is the Secure Payment Confirmation PIN, SMS-verified setup, per-signer status, safe failure modes.

Back-office approval where policy requires it

The second set of eyes belongs to the institution. Payments route to back-office approval when your policy says they should, by screening outcome, by limit, by client, and land in queues where operations reviews, approves, amends or investigates, with intervention possible on payments in flight. Maker-checker is not a checkbox here; it is how the payment lifecycle is built.

RBAC and segregation of duties across two domains

Client access and back-office access live in separate domains, a structural wall, not a permission setting. Inside each, role-based access control gates what a person sees and does: operations, finance, compliance and support each work within their role, clients within their mandates, and every action on either side is attributable in the audit trail.

Pricing and routing changes, separately audited

Money movement is not the only thing worth two pairs of eyes. Changes to price lists and to money routing, the commercially sensitive levers, carry their own separate audit on top of the platform’s general history: who changed what, when, with validity periods on pricing making every historical charge reconstructible. The controls that govern payments also govern the settings that shape them.

Four-eyes controls FAQ

What does four-eyes mean in practice here?
Two independent controls on money movement: the client’s own signatory mandates approve the instruction, and back-office approval applies wherever your policy routes a payment for review.
Approval rules are configurable per client, who initiates, who signs, how many signatures which operations need, and signing works on web and mobile alike.
When your policy says so: screening outcomes, limits and client-level rules route payments to back-office queues, where they are reviewed, approved, amended or investigated, with intervention possible in flight. Transaction monitoring.
Structurally: client and back-office access are separate domains, and role-based access controls what each role, operations, finance, compliance, support, can see and do inside them.
The commercially sensitive ones especially: pricing and money-routing changes are separately audited, with validity periods and approval trails making any historical state reconstructible.
Administrative actions are part of the audit trail like everything else, full history across payments, signatures, ledger entries, provider exchanges and admin actions, every action attributable to a person.

Watch four eyes land on one payment

A mandate signature, a policy hold, a back-office approval, the trail behind all three, the control loop, live.

Book a Demo  ·  The Compliance Suite.