Two-Person Integrity: When Dual Custody Applies to Keys and Credentials
Updated: 2 days ago
Every high-consequence loss shares one feature: a single person, acting alone, had enough access to cause it. Two-person integrity (TPI), sometimes called dual custody, is the discipline designed to break that pattern. In federal physical security, it shows up in classified key control, weapons storage, and nuclear materials programs, but the underlying principle applies equally to master keys, PACS administrative credentials, and credential stock. Blue Violet Security, LLC (BVS) helps facilities apply TPI where the risk actually warrants it, using system design instead of doubling headcount.
Where TPI Applies in Physical Security
Dual custody earns its cost when a single compromise would be catastrophic or undetectable. Typical applications:
Master key and grand master key storage: no individual removes or returns a master key ring alone.
PACS administrative accounts: no one admin account can create credentials, change access groups, or export the credential database unobserved.
Credential and badge stock: issuance and destruction of blank and retired credentials requires two signatures.
Video retention archives: deletion of surveillance evidence requires dual authorization so no single administrator can erase an incident.
The Design Problem
Naive TPI implementations fail on logistics. If every sensitive action requires two people, schedules, leave, and shift gaps will eventually produce a workaround, and the workaround is the vulnerability. Effective programs design around it:
Separation enforced by the system, not the honor system. The PACS can require a second credential or supervisor PIN for defined administrative actions. The door controller can require dual badge for defined high-security openings.
Alternates, not heroes. Every TPI position has trained alternates, so absence never justifies an exception.
Logging that reflects both parties. Dual-authorized events record both identities. An action with one ID where two are required is an alertable anomaly, not an assumption to explain later.
The Audit View
Assessors probe TPI the same way attackers do: by looking for the exception path. They will ask who can act alone at 0200, during a holiday stand-down, or when the second custodian resigns. If the answer is "any administrator, if they're patient," the control exists on paper only. The systems that pass are the ones where the technical enforcement makes solo action impossible rather than merely prohibited.
Recommendations
Inventory your dual-custody candidates: master keys, admin accounts, credential stock, evidence archives.
Enforce separation technically wherever the platform supports it.
Log both identities on dual-authorized events.
Test the exception path annually, the way an assessor will.
Schedule a Consultation with Blue Violet Security to evaluate where two-person integrity should be enforced in your facility.
This content is provided for general informational purposes only and does not constitute legal or regulatory advice. Compliance requirements and regulations are subject to change. Blue Violet Security, LLC recommends consulting with appropriate legal and regulatory counsel before making compliance determinations.



Comments