Principles
When designing this system we always need to take in account these basic principles:
- Dual Control, every action has to be controlled by two people.
- 1. Four eyes is a variation where every action is seen by two people.
- Privacy, reduce the private information we keep to the minimal.
- File a dispute, everything that is too complex for documentation or software should be kicked across to Dispute resolution (Arbitration)
Subsidiary Principles
- Every support action should be authorised by a token.
- There is no direct database query access provided to anyone.
- The Arbitrator has no direct access to the information.
- The system is not perfect nor complete; undefined or exceptional cases will be handled in an emergency by the sysadms.
Additionally there are other principles we have to consider.