Secure Access OTP

A two-person, biometric-verified vault access app for cash management teams. It replaces call center-issued codes with in-app verification and one-time codes generated directly from your Lock Management System.

Secure Access OTP Vault Authentication
SECURE VAULT ACCESS FLOW

How Secure Access OTP Opens a Vault

1

Daily Schedule Set

A coordinator lists today's ATM replenishments in the Daily Scheduler, or a helpdesk agent issues a trouble ticket. Until then, the ATM is not visible to the team at all.

2

Team Selects the ATM

On arrival, the team opens the app and selects the ATM from today's list.

3

Lock & Vehicle Confirmed

The app auto-fetches the lock serial number and the armoured vehicle number logged at trip start. The team confirms both are correct.

4
Team Leader

Security Question

The Team Leader is asked one randomly selected question from a bank of about 20 pre-defined questions, and must choose the correct answer from three options to continue.

5
Team Leader

Face Scan

The app opens the front camera and verifies the Team Leader's identity through server-side facial recognition.

6
Supervisor

Password & Face Scan

The phone is handed to the Supervisor, who enters a fixed 4-digit password and completes their own facial scan.

7

Geofence Check & Code Request

The app confirms the armoured vehicle is within the required radius of the ATM, then requests a one-time code from the Lock Management System.

8

Vault Opens

The team enters their Dallas key, its 4-digit PIN, and the 8-digit one-time code on the physical lock to open the vault.

SECURITY ARCHITECTURE

Six Independent Checks Before a Vault Opens

No single person, password, or device is ever enough on its own — every access request has to clear all six.

01

Pre-Authorization Gating

An ATM only appears in the app once a coordinator has scheduled it or a helpdesk agent has issued a ticket for it — nothing is accessible by default.

02

Two-Person Authorization

The Team Leader and Supervisor are each verified independently — no single team member can request a code alone.

03

Knowledge Factor

A randomized security question for the Team Leader and a fixed 4-digit password for the Supervisor — two different checks, two different people.

04

Biometric Verification

Facial recognition confirms both the Team Leader and Supervisor, matched server-side through a third-party recognition service.

05

Geofencing

The armoured vehicle's position must fall within the required radius of the ATM before any code request is sent.

06

One-Time Code from the LMS

The 8-digit code is generated fresh by the Lock Management System for that attempt only, and paired with the physical Dallas key PIN at the lock.

WHY WE REPLACED THE CALL CENTER

Built to Remove the Call Center Bottleneck

Old Way

Call Center-Issued Codes

  • Requires hiring and staffing a large call center team around the clock
  • Human agents perform security checks manually — inconsistent and error-prone
  • Codes are read aloud over the phone with no biometric or location verification
  • A call can be answered without confirming the team is actually scheduled for that ATM
  • One agent, one call — no independent second check before a code is issued
Secure Access

Secure Access OTP

  • No human call center needed — the code comes from the app and the LMS directly
  • Team Leader and Supervisor are both independently verified before any code is issued
  • Server-side facial recognition confirms identity, not just a voice on a call
  • The armoured vehicle's location is checked before a code can be requested
  • An ATM only appears in the app once it has been scheduled or ticketed — no exceptions
BUILT FOR EVERY ROLE

What Each Role Gets From Secure Access OTP

For CMC Coordinators

  • Set the day's replenishment and maintenance list each morning in the Daily Scheduler
  • No team sees or accesses an ATM that hasn't been explicitly scheduled
  • Full oversight of which teams accessed which vaults, and when

For Helpdesk Agents

  • Issue trouble tickets for unscheduled, ad-hoc vault access requests
  • The same two-person, biometric, and geofence checks apply to ticketed access
  • Every ticket-based access is logged alongside scheduled visits

For Field Teams

  • One Android app on the PDA or a standard phone — no separate hardware token
  • Clear step-by-step prompts guide the Team Leader and Supervisor through verification
  • The 8-digit one-time code and Dallas key PIN are the only manual entries at the lock
INTEGRATION

Fits Into the Vault Infrastructure You Already Run

Secure Access OTP connects directly to the systems your cash management operation already depends on.

Lock Management System Integration

Connects directly to your LMS to request and generate one-time codes for one-time-lock vaults, primarily S&G with KABA also supported.

Third-Party Facial Recognition

All biometric matching happens server-side through an integrated facial recognition service — never processed on the device itself.

Android Platform

Runs on the Android PDAs field teams already carry, as well as standard Android phones — no new hardware required.

Three Web Consoles

An Admin console for master data, a Daily Scheduler for coordinators, and a Helpdesk console for ad-hoc ticketing.

AUDIT & COMPLIANCE

Every Access Independently Verified and Logged

Secure Access OTP is built around dual sign-off and a full verification trail, so your compliance team has a clear record of exactly how every vault was opened.

Two-Person Sign-Off Logged

Every vault access records the Team Leader's and Supervisor's verification as two separate, independent events.

Full Verification Trail

Security question responses, face-match results, geofence checks, and code issuance are all logged for every attempt, pass or fail.

Schedule-Gated Access

Every access ties back to who scheduled it in the Daily Scheduler or which helpdesk agent issued the ticket for it.

No Reusable Codes

Every one-time code is generated fresh from the LMS for that specific attempt, lock, and vehicle position.

FAQ

Common Questions From Cash Management Teams

The app stops the process immediately. Access cannot continue on an incorrect answer, and the failed attempt is logged.

Yes — both must independently complete their own verification step and facial scan on the same device before a code is generated.

The app will not request a one-time code from the LMS until the vehicle's position matches the required radius.

No. The ATM won't appear in the app until a coordinator lists it in the Daily Scheduler or a helpdesk agent issues a trouble ticket for it.

All facial matching is performed server-side by the integrated third-party recognition service, never on the device itself.

The application integrates with Lock Management Systems for one-time-lock vaults — primarily S&G, with KABA also supported.

2
Independent Verifications Per Access
100%
Server-Side Facial Verification
0
Call Center Agents Needed
20
Randomized Security Questions

How It Works

A production-grade, three-step workflow that eliminates coordination overhead.

Detect & Ingest

Incidents flow in from ATMs, monitoring systems, and bank operations.

  • Real-time incident detection
  • Multi-source ticket ingestion
  • Automated classification

Automate & Dispatch

Smart routing assigns the right engineer for the fastest resolution.

  • Proximity-based routing
  • Skill & workload matching
  • Instant field notifications

Measure & Improve

Live dashboards give banks, CMCs, and vendors a single source of truth.

  • SLA & KPI dashboards
  • Auditable job history
  • Continuous SLA optimisation
Al Rajhi Bank
Bank Albilad
ANB
Alinma Bank
ASPG
Riyad Bank
SNB
AS