Glossary · compliance and risk
What is four-eye approval?
Four-eye approval means a second authorised person has to approve an action before it takes effect. On money leaving a business it is the difference between a mistake and an incident, and it is why the control exists at all.
Why irreversibility makes this control matter more in crypto
In a bank, a wrong payment can often be recalled. There is a process, it is unpleasant, and it frequently works. That safety net absorbs a certain amount of human error.
A blockchain transfer has no such net. Once it confirms it is final, so the only place to catch an error is before it sends. Approval is that place.
At CoinGate the control appears in two shapes. Batch payouts can require a second authorised review before processing. And with multi-approval enabled on payout links, every new link starts as a draft: a link created in the dashboard needs one approver, and a link created over the API needs two distinct approvers other than the creator, because an API key does not identify a person.
That asymmetry is deliberate and worth understanding. Dashboard creation already identifies a human and confirms with a one-time code. An API call does not, so it takes more approvals to reach the same assurance.
Frequently asked questions
Is it always two people?
For a dashboard-created payout link, one approver other than the creator. For an API-created one, two distinct approvers. Batch payouts can require a second authorised review.
Why do API-created links need more approvals?
Because an API key authenticates an application rather than a person, so the creator is unknown. Two distinct approvers restore the assurance that dashboard creation already has.
What happens to drafts if we turn multi-approval off?
They are auto-cancelled and refunded in full. Nothing is left in an unapproved limbo.
Can the creator approve their own payout?
No. Approvers must be distinct from the creator, which is the entire point of the control.
