Multi-factor authentication requires more than one distinct kind of authentication factor — something one knows, has or is — before access; NIST’s current guidance requires, at its middle assurance level, two distinct factors and the offer of a phishing-resistant one.
| role | first permission | second permission |
|---|---|---|
| developer | merge code | deploy to production |
| head of desk | propose parameters | approve parameters |
| operations | create payments | release payments |
| site reliability | create venue keys | withdraw from wallets |
| trader | submit orders | amend trades |