forumNew topic

Should accounting and the manager encrypt accounts and passwords or keep them in plain text? How does the dual-signature rule ensure security?

ZZehra T***Member
Job title
Operations manager
Sector
Freight
Organization type
early-stage startup
Joined
Apr 2026
Message
68

Doki · Penetration test · 2025

#1

we're setting up a financial control system in a 5-person company. who should hold the bank account passwords? should the accountant and manager have the same or different passwords? i don't understand how the dual-signature rule works.

i don't want to slow down work while ensuring security.

should passwords be recorded in writing or kept in memory?

EEfe K***ExpertCommunity member
Joined
Feb 2023
Message
2
Most Helpful#2

Dual signature rule: Every payment transaction must be approved by 2 people. Ideally, the accountant and manager should have different accounts and passwords.

You can enable the 'dual control' setting in the banking system — the accountant requests the payment, the manager approves via SMS on their phone. This eliminates password sharing.

NEVER keep passwords in writing. Use an encrypted password manager (like BitWarden, KeePass). Only the manager and accountant should have access.

IIrmak M***Member
Job title
Technical service technician
Sector
Consulting
Organization type
sole proprietorship
Joined
Apr 2023
Message
104

Doki · Backup setup · 2023

#3

we share each other's passwords too, but since there's a risk we added phone confirmation at the bank.. but now it's a bit more comfortable

İİsmetMember
Job title
Logistics Manager
Joined
Nov 2023
Message
112
#4

Setting up a dual signature system: 1. Enable 'Dual Approval' in the bank app 2. Accountant: request the transaction 3. Manager: approve with SMS code 4. Transfer is made 5. Archive the report

ÜÜlkü A***New memberCommunity member
Joined
Jul 2026
Message
70
#5

Password manager: Open BitWarden (encrypted), create a shared vault group for the accountant and manager. Access logs are kept automatically.

KKaan G***ExpertCommunity member
Joined
Jun 2023
Message
94
#6

sharing passwords but writing them in plain text isn't secure. anyway it's better if you use a locked file or vault

HHavva M***Expert
Job title
Front office accounting
Sector
Media and publishing
Organization type
chain store
Joined
Sep 2022
Message
197
#7

if the accountant and manager get together, they can change the password and steal your money, right?

HHakan U***MemberCommunity member
Joined
Apr 2024
Message
43
#8

Dual signature control mechanism: It's done based on risk. High-risk transfers require more approvals.

EEbru Ö***Member
Job title
Supply chain manager
Sector
Glass
Organization type
early-stage startup
Joined
Oct 2025
Message
302
#9

Yes, that's exactly how it is with dual signature rule. Start with a small trial; don't commit to everything at once.

When making decisions, write down the worst-case scenario too, not just the best. Good luck with that.

VVildan Ö***Member
Job title
Secretary
Sector
Retail
Organization type
family business
Joined
Dec 2024
Message
66
#10

ive been dealing with this for a long time. the answer varies greatly by industry; therre is no one-size-fits-all rule.

processes without records never improve because you don't know what to fix.

VVildan Y***Member
Job title
Content Editor
Sector
Retail
Organization type
20-person company
Joined
Nov 2024
Message
70
#11

Here's how it went for us. If 2FA is on, a stolen password alone is useless.

The biggest time-waster for us was not knowing who had the final say.

VVildan O***Member
Job title
Export manager
Sector
Furniture manufacturing
Organization type
boutique agency
Joined
Oct 2025
Message
210

Doki · Incident response support · 2026

#12

We need to make a distinction here. The answer varies greatly by industry; there is no one-size-fits-all rule.

That's all, sorry if I went on too long.

BBurak G***Member
Job title
Logistics planning
Sector
Livestock
Organization type
early-stage startup
Joined
Oct 2024
Message
29
#13

We've heard this a lot, but it never happened like that for us. Mistakes made on the dual signature rule side are usually reversible but expensive.

If you scold false alarms, nobody will report again. I'm also curious if anyone does it differently.

ZZehra B***MemberCommunity member
Joined
Jun 2024
Message
76
#14

Here's how it went for us. If you get three different answers on a topic, the question was asked wrong.

If I were you, I'd go this route.

HHakan U***ExpertCommunity member
Joined
Sep 2024
Message
86
#15

There are three things to check when doing this. Mistakes made on the dual signature rule side are usually reversible but expensive.

This is my opinion, I'm not claiming it's absolute truth.

KKader T***Expert
Job title
Accounting clerk
Sector
E-commerce
Organization type
40-person manufacturing company
Joined
Jul 2023
Message
219
#16

Generally correct, but one part is missing. If its your first time start small; scaling comes later.

The real issue isnt the number, but what its based on. This is my opinion Im not claiming its absolute truth.

NNecati A***MemberCommunity member
Joined
Jan 2025
Message
5
#17

i agree.

ÖÖzge Ç***Member
Job title
Administrative manager
Sector
Accounting & advisory
Organization type
120-person company
Joined
Nov 2024
Message
2
#18

Great work.

GGamze Ç***ExpertCommunity member
Joined
May 2023
Message
20
#19

There is something to watch out for. Processes without records never improve, because you don't know what to fix.

If I were you, I'd go this route.

MMeryem S***Member
Job title
Human Resources Specialist
Sector
E-commerce
Organization type
two-branch business
Joined
Dec 2024
Message
303
#20

Let me summarize what's been said so far. Most incidents start with a leaked password, not a vulnerability.

Just leaving this note, it might be useful.

Reply