The two-person rule for AI agents: overrides, dual authorisation, and Meta's Rule of Two

Some actions need two authorised people, acting separately, before they happen. That is the two-person rule. For AI agents it matters most in one place: the override. Your rules stop an action. Someone wants it through anyway. One person should not be enough.
In one sentence: your rules can be overridden, but never by one person alone, and never without both names in the record.
Where it comes from
NIST's catalogue of security controls carries it as AC-3(2), dual authorization. "Dual authorization, also known as two-person control, reduces risk related to insider threats. Dual authorization mechanisms require the approval of two authorized individuals to execute"1. The same text adds a warning that matters for agents: "To reduce the risk of collusion, organizations consider rotating dual authorization duties"1.
Your finance team knows it as the second signature above a threshold, or maker-checker in payments. Its cousin is separation of duties, AC-5 in the same catalogue. It "addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion"1. Separation of duties splits a process across people. The two-person rule puts two people on one decision.
Both assumed humans on every side. Agents change who acts first.
What it actually is, for an agent
An agent working under written rules meets three moments where someone wants a different outcome. Each is where the two-person rule belongs.
Overriding a refusal. Your rules said no. The agent tried to pay a supplier whose bank details changed yesterday. The control plane stopped it. Your AP lead is sure it is fine. The supplier phoned. One person's certainty is exactly what an attacker engineers. Two names, from two roles, before the block lifts for this one case.
Loosening a limit. The autopay limit is 250.00. The team wants 1,000.00. That is a change to the rules, not a decision about a case. It should be harder than tightening. One person can lower a limit anytime. Raising it takes two.
Changing the approver. Whoever gets the holds is the human control. Swapping that name changes the control itself. Two names.
The table draws the line. Amounts are illustrative.
| Situation | Who decides | Why |
|---|---|---|
| Ordinary hold (2,400.00, over a 250.00 limit) | One named approver | Routine judgment. The rules expected it |
| Override a refusal (pay despite the bank-change block) | Two named people, different roles | The rules did not expect it, or an attacker did |
| Raise a limit, widen scope, add a tool | Two named people, one from risk | Changes what the agent does alone from now on |
| Lower a limit, narrow scope, remove a tool | One person | Tightening should always be easy |
| Change the approver or cover | Two named people | Changes the control, not the case |
The asymmetry is deliberate. If loosening costs the same as tightening, your rules drift looser. Loosening is what people ask for at 5pm on the last day of the month.
Meta's Rule of Two is a different rule
In October 2025 Meta's security team published the "Agents Rule of Two". It is not about approvers. It says "agents must satisfy no more than two of the following three properties within a session to avoid the highest impact consequences of prompt injection"2. The three: the agent "can process untrustworthy inputs", "can have access to sensitive systems or private data", and "can change state or communicate externally"2. It builds on Simon Willison's "lethal trifecta", which named the same ingredients for data theft through an agent3.
Meta's conclusion links the two rules. If an agent needs all three in one session, "the agent should not be permitted to operate autonomously and at a minimum requires supervision"2. Meta names human-in-the-loop approval as one way to supply it2.
So Meta's rule is a design rule about what an agent may combine. The two-person rule is an approval rule about who may lift a block. Your AP agent reads invoices (untrusted), reads the ERP (sensitive) and schedules payments (changes state). It breaks Meta's rule by design. That is why it needs a hold. The two-person rule governs what happens when someone pushes past the hold.
Meta also says what its rule does not do. It "should not be viewed as sufficient for protecting against other threat vectors common to agents"2. It "is a supplement" and "not a substitute" for "common security principles such as least-privilege"2. Read that as permission to keep the older controls.
What it is good at, and what it is not
Good at. Removing the single point of failure every other control leaves. The trusted insider. The tired approver. The person whose login was phished. It makes the record of an override useful: two names and two timestamps are hard to explain away. And it slows rule changes just enough that someone reads them.
Not good at. Speed. The payment run has to clear by 15:00 and both signers are in meetings. The rule costs money. NIST's audit-function version says organisations do not require dual authorization "when immediate responses are necessary to ensure public and environmental safety"1. Your AP run is not that. Design the ordinary path so overrides are rare. Give the pair a time limit, after which the case escalates instead of waiting.
Where it goes wrong. Two people who always sign together. NIST's rotation advice exists because a fixed pair is one decision with two signatures. Rotate the second name, or draw it from another function.
What workflow tools give you. Power Automate has an approval type where "if any approver rejects, the approval request is considered rejected for all approvers"4. That is a two-person rule for an ordinary approval. It works. It does not tell an override from a routine hold. It does not bind the second signature to a rule change. You can build that yourself. Most teams do not.
What to check
- /01
Can one person unblock an action the rules refused? If yes, the rules are advice.
- /02
Is raising a limit harder than lowering one? Ask to watch both.
- /03
Which two roles can override? Are they ever one person's two accounts?
- /04
Does the record show both names, both times, and each person's reason?
- /05
How are the pairs rotated?
- /06
What is the time limit on a pending override, and where does it escalate?
Where it is going
Two-person overrides are turning up inside agent platforms as a checkbox. That is progress. The gap we see: the checkbox rarely covers rule changes. The override is dual-signed. The rule edit that would make it unnecessary next time takes one admin. Our view is auditors will ask about that second case first. It changes the control for good.
Gatehouse fit
Gatehouse needs two names to override a block. The override goes into the same record as the run it changed, chained by SHA-256, so nobody can quietly remove it. Rule changes go into the signed rules, and only the signed version is enforced on the next run. The Gatehouse page shows the flow on a simulated run.
At a glance
| Category | Controls |
|---|---|
| Also called | Dual authorisation, two-person control, four-eyes principle, maker-checker |
| Borrowed from | NIST SP 800-53 AC-3(2). Maker-checker in payments |
| Not to be confused with | Meta's Agents Rule of Two (a capability design rule, October 2025) |
| Key standards or docs | NIST SP 800-53 Rev. 5 AC-3(2), AC-5. Meta AI blog. Willison's lethal trifecta |
| Typical owner | Risk or internal audit defines the pairs. The process owner and a second function sign |
| The one test | Can one person lift a block, or raise a limit, alone? |
Sources
- [1]NIST SP 800-53 Rev. 5, AC-3(2) Dual Authorization and AC-5 Separation of Duties (PDF), September 2020nvlpubs.nist.gov In text
- [2]Agents Rule of Two: A Practical Approach to AI Agent Security, Meta, 31 October 2025ai.meta.com In text
- [3]The lethal trifecta for AI agents, Simon Willison, 16 June 2025simonwillison.net In text
- [4]Create an approval flow that requires everyone to approve, Power Automate docs, Microsoft Learnlearn.microsoft.com In text
Read next

What is an agent approval policy?
An approval policy decides which agent actions go ahead, which wait for a person, and which never happen. Most teams have a paragraph. You need a table.

What is an agent control plane?
An agent control plane checks every action an AI agent wants to take against your rules before it runs, holds the hard ones for a named person, and records the result.

What is an agent permission manifest?
A permission manifest is the signed list of what an AI agent may touch, spend and decide alone. Anything not on the list is refused. What one contains, and why a prompt is not one.