surehand
All articlesControls

The two-person rule for AI agents: overrides, dual authorisation, and Meta's Rule of Two

Reference6 min readSurehand

Some actions need two authorised people, acting separately, before they happen. That is the two-person rule. For AI agents it matters most in one place: the override. Your rules stop an action. Someone wants it through anyway. One person should not be enough.

In one sentence: your rules can be overridden, but never by one person alone, and never without both names in the record.

Where it comes from

NIST's catalogue of security controls carries it as AC-3(2), dual authorization. "Dual authorization, also known as two-person control, reduces risk related to insider threats. Dual authorization mechanisms require the approval of two authorized individuals to execute"1. The same text adds a warning that matters for agents: "To reduce the risk of collusion, organizations consider rotating dual authorization duties"1.

Your finance team knows it as the second signature above a threshold, or maker-checker in payments. Its cousin is separation of duties, AC-5 in the same catalogue. It "addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion"1. Separation of duties splits a process across people. The two-person rule puts two people on one decision.

Both assumed humans on every side. Agents change who acts first.

What it actually is, for an agent

An agent working under written rules meets three moments where someone wants a different outcome. Each is where the two-person rule belongs.

Overriding a refusal. Your rules said no. The agent tried to pay a supplier whose bank details changed yesterday. The control plane stopped it. Your AP lead is sure it is fine. The supplier phoned. One person's certainty is exactly what an attacker engineers. Two names, from two roles, before the block lifts for this one case.

Loosening a limit. The autopay limit is 250.00. The team wants 1,000.00. That is a change to the rules, not a decision about a case. It should be harder than tightening. One person can lower a limit anytime. Raising it takes two.

Changing the approver. Whoever gets the holds is the human control. Swapping that name changes the control itself. Two names.

The table draws the line. Amounts are illustrative.

SituationWho decidesWhy
Ordinary hold (2,400.00, over a 250.00 limit)One named approverRoutine judgment. The rules expected it
Override a refusal (pay despite the bank-change block)Two named people, different rolesThe rules did not expect it, or an attacker did
Raise a limit, widen scope, add a toolTwo named people, one from riskChanges what the agent does alone from now on
Lower a limit, narrow scope, remove a toolOne personTightening should always be easy
Change the approver or coverTwo named peopleChanges the control, not the case

The asymmetry is deliberate. If loosening costs the same as tightening, your rules drift looser. Loosening is what people ask for at 5pm on the last day of the month.

Meta's Rule of Two is a different rule

In October 2025 Meta's security team published the "Agents Rule of Two". It is not about approvers. It says "agents must satisfy no more than two of the following three properties within a session to avoid the highest impact consequences of prompt injection"2. The three: the agent "can process untrustworthy inputs", "can have access to sensitive systems or private data", and "can change state or communicate externally"2. It builds on Simon Willison's "lethal trifecta", which named the same ingredients for data theft through an agent3.

Meta's conclusion links the two rules. If an agent needs all three in one session, "the agent should not be permitted to operate autonomously and at a minimum requires supervision"2. Meta names human-in-the-loop approval as one way to supply it2.

So Meta's rule is a design rule about what an agent may combine. The two-person rule is an approval rule about who may lift a block. Your AP agent reads invoices (untrusted), reads the ERP (sensitive) and schedules payments (changes state). It breaks Meta's rule by design. That is why it needs a hold. The two-person rule governs what happens when someone pushes past the hold.

Meta also says what its rule does not do. It "should not be viewed as sufficient for protecting against other threat vectors common to agents"2. It "is a supplement" and "not a substitute" for "common security principles such as least-privilege"2. Read that as permission to keep the older controls.

What it is good at, and what it is not

Good at. Removing the single point of failure every other control leaves. The trusted insider. The tired approver. The person whose login was phished. It makes the record of an override useful: two names and two timestamps are hard to explain away. And it slows rule changes just enough that someone reads them.

Not good at. Speed. The payment run has to clear by 15:00 and both signers are in meetings. The rule costs money. NIST's audit-function version says organisations do not require dual authorization "when immediate responses are necessary to ensure public and environmental safety"1. Your AP run is not that. Design the ordinary path so overrides are rare. Give the pair a time limit, after which the case escalates instead of waiting.

Where it goes wrong. Two people who always sign together. NIST's rotation advice exists because a fixed pair is one decision with two signatures. Rotate the second name, or draw it from another function.

What workflow tools give you. Power Automate has an approval type where "if any approver rejects, the approval request is considered rejected for all approvers"4. That is a two-person rule for an ordinary approval. It works. It does not tell an override from a routine hold. It does not bind the second signature to a rule change. You can build that yourself. Most teams do not.

What to check

  1. /01

    Can one person unblock an action the rules refused? If yes, the rules are advice.

  2. /02

    Is raising a limit harder than lowering one? Ask to watch both.

  3. /03

    Which two roles can override? Are they ever one person's two accounts?

  4. /04

    Does the record show both names, both times, and each person's reason?

  5. /05

    How are the pairs rotated?

  6. /06

    What is the time limit on a pending override, and where does it escalate?

Where it is going

Two-person overrides are turning up inside agent platforms as a checkbox. That is progress. The gap we see: the checkbox rarely covers rule changes. The override is dual-signed. The rule edit that would make it unnecessary next time takes one admin. Our view is auditors will ask about that second case first. It changes the control for good.

Gatehouse fit

Gatehouse needs two names to override a block. The override goes into the same record as the run it changed, chained by SHA-256, so nobody can quietly remove it. Rule changes go into the signed rules, and only the signed version is enforced on the next run. The Gatehouse page shows the flow on a simulated run.

At a glance

CategoryControls
Also calledDual authorisation, two-person control, four-eyes principle, maker-checker
Borrowed fromNIST SP 800-53 AC-3(2). Maker-checker in payments
Not to be confused withMeta's Agents Rule of Two (a capability design rule, October 2025)
Key standards or docsNIST SP 800-53 Rev. 5 AC-3(2), AC-5. Meta AI blog. Willison's lethal trifecta
Typical ownerRisk or internal audit defines the pairs. The process owner and a second function sign
The one testCan one person lift a block, or raise a limit, alone?

Sources

  1. [1]NIST SP 800-53 Rev. 5, AC-3(2) Dual Authorization and AC-5 Separation of Duties (PDF), September 2020nvlpubs.nist.gov In text
  2. [2]Agents Rule of Two: A Practical Approach to AI Agent Security, Meta, 31 October 2025ai.meta.com In text
  3. [3]The lethal trifecta for AI agents, Simon Willison, 16 June 2025simonwillison.net In text
  4. [4]Create an approval flow that requires everyone to approve, Power Automate docs, Microsoft Learnlearn.microsoft.com In text

Read next

[ your next step ]

Bring us the queue nobody wants.

One process, studied in writing. You keep the document, whatever it says.

support@surehand.io