Your approval code

A payment at or above the high-value threshold is captured and then HELD: nothing posts until you, the user who initiated it, re-confirm it by entering your own personal approval code. This page is where you set that code and rotate it.

The threshold in force is USD 50,000.00 (module default). After 5 incorrect attempts a code is locked for 15 minutes, and while it is locked even the correct code is refused.

The code itself is never stored. What is kept is a salted scrypt hash, compared with a timing-safe check; it is never logged, never shown on any screen and never returned by the API. If you forget it, an administrator can reset it — they set a new one without ever learning the old.

Set or rotate a code

Daniel Silva has no approval code yet, so they cannot confirm a high-value payment.

864 characters, no spaces, with at least one letter and one digit.

An administrator can set a new code without the old one and clear any lock-out. The reset is written to the audit trail naming the administrator; nobody, including them, can read the previous code.

Approval-code status across the desk

Showing 4 of 4 active staff

Status only — whether a code exists, when it was last rotated and used, and whether it is locked. No code, and no recoverable form of one, appears anywhere here.

Each listed active staff user with the state of their personal step-up approval code
Staff userCodeLast rotatedLast usedFailed attempts

Daniel Silva

approver

Not set

Cannot confirm a high-value payment until a code is set.

Never used0 of 5

Mei Chen

compliance

Not set

Cannot confirm a high-value payment until a code is set.

Never used0 of 5

Rachel Okafor

operator

Not set

Cannot confirm a high-value payment until a code is set.

Never used0 of 5

Sola Adeyemi

admin

Not set

Cannot confirm a high-value payment until a code is set.

Never used0 of 5

Sample book disclosure: the staff users listed here are seeded demonstration data created by this module. No approval code is seeded — a published secret would not be a control, so each user sets their own.