[{"data":1,"prerenderedAt":23},["ShallowReactive",2],{"blog-article-dual-control-that-survives-tuesday":3},{"id":4,"slug":5,"body":6,"html":7,"title":8,"description":9,"category":10,"tags":11,"author":15,"date":16,"year":17,"month":18,"quarter":19,"status":20,"featured":21,"series":22,"seriesOrder":19},"2026\u002F08\u002Foffers\u002Fdual-control-that-survives-tuesday","dual-control-that-survives-tuesday","\nMost “dual control” is a slide.\n\nIt dies when:\n\n- Shared admin is still on.\n- The maker and checker are the same person after hours.\n- The tool allows a bypass that nobody logs.\n- The ticket closed without the evidence primary key.\n\nTuesday is the test. Volume is up. Someone is on leave. The corridor is hot. Policy PDFs do not move.\n\n## Production dual control has four parts\n\n1. **Policy that the system can enforce** (or a manual gate that is actually staffed).\n2. **Segregation that survives staffing gaps** — named roles, not heroics.\n3. **Exception path** with a register, not a private chat.\n4. **Evidence** that the dual control event happened — linked to the ticket.\n\nIf any one of those is missing, you have theatre.\n\n## What a sprint does\n\nWe do not sell a new custody product. We design dual control **on the stack you already run** (or have contracted), map the as-is failures, and leave a to-be model plus control matrix for **one** workflow.\n\nWiring configuration often follows as Integration SI — after the design is accepted, or via a vendor who is stuck on implementation.\n\n## Red flags in a fit call\n\n- “We have dual control” but cannot show last week’s maker\u002Fchecker record.\n- Owner keys discussed as something we would hold. (We will not.)\n- Request to “make the tool compliant” without naming the workflow.\n\n[Offers](https:\u002F\u002Ffazezero.com\u002Foffers) · [How we work](https:\u002F\u002Ffazezero.com\u002Fhow-we-work)\n\n**Next step:** If dual control fails on a real book this month, say so on the fit call. That is a production problem, not a branding problem.\n\n*Fence: We configure guidance on client-owned systems. No owner\u002Froot admin. No keys.*\n","\u003Cp>Most “dual control” is a slide.\u003C\u002Fp>\n\u003Cp>It dies when:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Shared admin is still on.\u003C\u002Fli>\n\u003Cli>The maker and checker are the same person after hours.\u003C\u002Fli>\n\u003Cli>The tool allows a bypass that nobody logs.\u003C\u002Fli>\n\u003Cli>The ticket closed without the evidence primary key.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Tuesday is the test. Volume is up. Someone is on leave. The corridor is hot. Policy PDFs do not move.\u003C\u002Fp>\n\u003Ch2>Production dual control has four parts\u003C\u002Fh2>\n\u003Col>\n\u003Cli>\u003Cstrong>Policy that the system can enforce\u003C\u002Fstrong> (or a manual gate that is actually staffed).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Segregation that survives staffing gaps\u003C\u002Fstrong> — named roles, not heroics.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Exception path\u003C\u002Fstrong> with a register, not a private chat.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Evidence\u003C\u002Fstrong> that the dual control event happened — linked to the ticket.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>If any one of those is missing, you have theatre.\u003C\u002Fp>\n\u003Ch2>What a sprint does\u003C\u002Fh2>\n\u003Cp>We do not sell a new custody product. We design dual control \u003Cstrong>on the stack you already run\u003C\u002Fstrong> (or have contracted), map the as-is failures, and leave a to-be model plus control matrix for \u003Cstrong>one\u003C\u002Fstrong> workflow.\u003C\u002Fp>\n\u003Cp>Wiring configuration often follows as Integration SI — after the design is accepted, or via a vendor who is stuck on implementation.\u003C\u002Fp>\n\u003Ch2>Red flags in a fit call\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>“We have dual control” but cannot show last week’s maker\u002Fchecker record.\u003C\u002Fli>\n\u003Cli>Owner keys discussed as something we would hold. (We will not.)\u003C\u002Fli>\n\u003Cli>Request to “make the tool compliant” without naming the workflow.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Ffazezero.com\u002Foffers\">Offers\u003C\u002Fa> · \u003Ca href=\"https:\u002F\u002Ffazezero.com\u002Fhow-we-work\">How we work\u003C\u002Fa>\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Next step:\u003C\u002Fstrong> If dual control fails on a real book this month, say so on the fit call. That is a production problem, not a branding problem.\u003C\u002Fp>\n\u003Cp>\u003Cem>Fence: We configure guidance on client-owned systems. No owner\u002Froot admin. No keys.\u003C\u002Fem>\u003C\u002Fp>\n","Dual control that survives Tuesday","Dual control that only exists in a policy PDF fails on a busy Tuesday. Production dual control is enforced, staffed, and evidenced.","offers",[12,13,14],"governance","operations","compliance","fazezero-editorial","2026-08-24T00:00:00.000Z",2026,8,3,"published",false,"product-offers",1789210410748]