Protection objective
A sensitive action should not depend on one condition, credential, component, or person when one compromise could cause unacceptable harm. Require independent conditions or authorities so that one failure is insufficient.
The principle
Separation of privilege can require two people, two keys, two systems, or two independent facts. Multi-factor authentication is one example, but the principle also applies to approvals, deployment, key recovery, policy changes, and financial actions. Independence is the important property.
Design independent conditions
State the action and harm. Choose conditions controlled through different failure paths. Ensure one actor cannot silently satisfy both roles. Bind each approval to the exact operation, resource, parameters, and time. Record who approved and what was executed.
Failure and limits
Two checks that depend on the same account, device, administrator, or identity provider may fail together. Approval fatigue can turn a second actor into a rubber stamp. Separation adds delay and availability dependencies, so recovery needs its own controlled process.
Pomerium boundary
Pomerium can require multiple independent policy criteria for route access. A business action that needs dual approval must usually be enforced by the application because it owns the action and workflow state. Route access alone does not prove application approval.
Evaluation checklist
- Is the sensitive action and unacceptable harm explicit?
- Are the required conditions independent in control and failure mode?
- Can one actor or compromised system satisfy all conditions?
- Are approvals bound to the exact action and time?
- Does recovery preserve separation or add a reviewed exception?
