skip to content

What does two-person approval add before opening a named employee's mailbox telemetry?

level: middleimportance: should knowfreq 47%

answer

  1. Requesting and authorising are different jobs
  2. Independence matters more than seniority
  3. The grant names subject, sources, window, expiry
  4. Ex ante approval, ex post query audit
  5. Unenforced approval is a form, not a control

basics

~20 s

It splits wanting the data from authorising it: the analyst who requests access cannot grant it. The recorded approval also bounds the access — named subject, named sources, a date range, an expiry — turning an open capability into a specific grant.

solid answer

~50 s

Two-person approval is separation of duties applied to reading a person. The analyst raises a request naming the subject, the sources, the fields, the time window and the case; a second person outside that analyst's chain — typically HR, legal or a privacy officer, sometimes the data owner — approves or refuses, and the approval is recorded against the case. That buys two things: no single member of the SOC can decide unilaterally to read a colleague's mail, and the access that happens is bounded and evidenced rather than open-ended. It has to be enforced by the platform, not by a form: if the grant is not what actually unlocks the data, people fill the form in afterwards. And it is an *ex ante* control only — it says what was permitted, not what was queried. The query audit is the *ex post* half, and you need both.

go deeper

for a junior

Know that reading a named employee's mailbox or endpoint data needs someone else's recorded approval, and that you name the subject, the sources, the dates and the case when you ask.

for a middle

Explain what the grant specifies and why the second approver must sit outside your chain, and separate the ex ante approval from the ex post query audit that shows what was actually run.

for a senior

Demonstrate enforcement thinking: the grant should be what unlocks the data, standing per-person access should be small, and break-glass should exist, be narrow and be reviewed.

for a principal

Be ready to defend where the approval authority sits, why refusals are a feature, and how targeted access is separated from estate-wide monitoring in whatever agreement governs the workforce.

## The control in one line Two-person approval (four-eyes) separates the person who wants targeted telemetry about a named human from the person who authorises it. In a SOC that matters because the same analyst can normally both want and take. ## What a good request and grant contain The request is not "give me access to Maria's data". It should name: - **the subject** — specific identifiers, not a team or a department; - **the sources** — mailbox audit records, endpoint process telemetry, sign-in logs, proxy, HR records; each is a separate decision; - **the fields** — metadata such as message headers and recipients is a different intrusion from message content, and "who ran which process" differs from "which URLs did they visit"; - **the time window** — the days that matter to the hypothesis, not "everything since they joined"; - **the case reference and the question** — one sentence stating what the access is meant to answer; - **an expiry** — the grant ends by itself. The approver's job is to test the scope against the question, refuse the parts that are not needed, and record the decision. A grant that is narrower than the request is a sign the control is working. ## Who the second person should be The useful property is independence, not seniority. The requesting analyst's own team lead shares the team's incentive to get the answer and often has no standing to weigh employment or privacy considerations. The strong choices are outside the security line: HR for employment matters, legal for anything that may end in discipline or litigation, a privacy or compliance officer for the data question, or the owner of the system holding the records. In some organisations an employee representative body is party to the standing agreement that defines when this is possible at all — approval then operates inside that agreement rather than instead of it. The subject's own line manager is usually a poor choice: they may be involved in what is being investigated, and telling them creates a tipping-off risk. ## Ex ante and ex post are different controls A recorded approval establishes that a second person authorised access of a stated shape. It does **not** establish that the analyst queried only within that shape. That is what the query audit shows, after the fact, by comparing the searches actually run against the approved subject, sources and window. Interviewers like this distinction because candidates routinely claim one control delivers both. A third piece completes it: the access should be technically bounded where possible — a temporary role, a scoped index or view, a time-limited grant that expires — so that the difference between the approval and what is reachable is small. ## Enforcement, or it is theatre If analysts already hold standing access to mailbox and endpoint telemetry and the approval is a ticket raised alongside, the control depends entirely on honesty and it will be discovered to be empty during the first case that matters. Make the grant the thing that unlocks the data: no approval, no read path. Standing access should be reduced to what genuinely must be available without approval — typically estate-wide detections and aggregate views, not per-person deep dives. ## Break-glass A control with no exception route gets bypassed. Design one: a named on-call approver, a break-glass grant that is deliberately narrow (short window, metadata only), automatic notification to the normal approver and to the audit function, and a mandatory review within a fixed period. Break-glass that is used weekly is a sign the ordinary path is too slow, not that the exception is working. ## What this control is not for Two-person approval governs **targeted access to a named person's records**. It is the wrong instrument for estate-wide detection: a rule that evaluates every endpoint's process telemetry is not a per-subject decision, and gating it behind per-person approval would stop the SOC functioning. That distinction — targeted access versus population-level detection — is usually the one the standing agreement with employee representatives draws, and confusing them is a common weak answer. ## Failure modes worth naming - **Rubber-stamping.** An approver who approves everything within a minute has converted the control into latency. Approvers need enough context, and refusals need to be possible and occasionally actual. - **Scope creep inside a live case.** The approved window quietly extends. Re-approve, and record it. - **The approver is unreachable**, so people learn to route around the control. - **Approval without an expiry**, which leaves a standing grant behind after the case closes. - **The subject is inside the approval chain**, which voids the whole thing.

  • A live insider case needs mailbox telemetry at 03:00 and the named approver is unreachable. What should happen?
    A pre-agreed break-glass path: a named on-call alternate approver, and failing that a deliberately narrow emergency grant — short window, metadata rather than content — that notifies the normal approver and the audit function automatically and is reviewed within a fixed period. Design it in advance. If break-glass is used routinely, the ordinary approval path is too slow and should be fixed rather than worked around.
  • Does two-person approval apply to a detection that runs across every employee's endpoint telemetry?
    No. Per-subject approval governs targeted access to a named person's records. A detection evaluating the whole estate is a population-level control, agreed once at the level of what the SOC may monitor at all, usually with employee representatives, and governed by what the rule outputs and who sees it. Gating estate-wide detection behind per-person approval would stop the SOC working, and confusing the two is a common weak answer.
  • How do you tell a real two-person approval from a rubber stamp?
    Look for refusals and narrowing: grants that come back smaller than the request, approvals with an expiry, and re-approval when a case widens. Look at time-to-approve — a consistent sub-minute turnaround on requests to read someone's mail means nobody is weighing anything. And check enforcement: if analysts can reach the data without the grant, the approval is documentation, not a control.

saying these in an interview costs you the question

  • Names the requesting analyst's own team lead as the approver
  • Claims approval proves the analyst only read what was approved
  • Leaves standing access in place alongside the approval ticket
  • Grants access with no time window, field limit or expiry
  • Applies per-person approval to estate-wide detections

context