← All posts

July 15, 2026 · Nick Krykunov

What is the four-eyes principle? (dual control for cloud teams)

The four-eyes principle means a sensitive action needs a second person to approve it before it happens, so no single individual can do it alone. Two sets of eyes, four eyes, see the action before it goes through. It catches honest mistakes and deliberate abuse in the same move, because the second person is a check the first can’t bypass on their own.

Four-eyes vs dual control

Four-eyes and dual control mean essentially the same thing, a second person is required for a sensitive action, and the terms are used interchangeably. Four-eyes usually describes review and approval: someone requests, someone else approves. Dual control often implies two people are physically needed to complete an action, the classic image being two keys turned at once to launch something.

The distinction rarely matters in a cloud team. What matters is the shared idea: for a high-stakes action, one person is not enough.

Where to apply it

The four-eyes principle earns its keep on a small set of actions and becomes a nuisance everywhere else. Reserve it for the things where a single mistake or a single bad actor causes real damage.

Approving privileged or emergency access is a natural fit, so one person can’t quietly grant themselves the keys. Changes to production are another. And the most important, most overlooked one: anything that disables a security control. If turning off your own guardrails takes only one person, then the guardrails are only ever one compromised account away from being switched off, which is why the off switch deserves a second pair of eyes more than almost anything else.

Does it slow teams down?

It can, if you apply it to everything, which is exactly why you don’t. Used narrowly, on the genuinely dangerous actions, the friction is small and it lands only where the stakes justify it.

The other half is wiring it into a tool the team already lives in. A four-eyes approval that means opening a separate console and chasing someone down will get resented and worked around. The same approval as a quick reaction in Slack is barely felt. The goal is a second person, not a second job.

Where Korvalis fits

Korvalis puts approvals for access into Slack, where your team already works, so a second person can approve a request without leaving their day. That’s the everyday version of four-eyes: access gets a check, and the check is fast.

The principle also applies to Korvalis’s own controls. Disabling protection is exactly the kind of high-severity action that shouldn’t rest on one person or one channel, and requiring a second approver for it is on our roadmap rather than shipped today, so we’d rather say that plainly than imply otherwise. The broader point stands: pair a second-person check on the dangerous actions with access that expires on its own and a guard that watches the session, and one person’s mistake stops being able to end your day.

Frequently asked questions

What is the four-eyes principle? A sensitive action needs a second person to approve it before it happens, so no single individual can do it alone.

How is it different from dual control? They mean essentially the same thing. Four-eyes usually describes review and approval; dual control often implies two people are needed to complete an action. In practice they’re used interchangeably.

Where should you apply it? On high-risk actions: approving privileged access, production changes, and anything that disables a security control. Not everywhere, or it becomes a bottleneck.

If a second pair of eyes on the dangerous actions sounds right, see how Korvalis handles approvals or join the waitlist.