Double factor authentication | Community
Skip to main content

Double factor authentication

  • May 12, 2026
  • 2 replies
  • 175 views

We need to implement a double approval process for FIN AI production releases.

Before any deployment goes into production, a second level of validation and authorization should be required to ensure proper security and quality control. This will allow Team Leads to have visibility and governance over changes being released.

Production deployments should never depend on a single person developing and pushing changes directly to production without an additional review and approval process.

2 replies

Forum|alt.badge.img+7

Hi ​@Jeremy Alfaro, Seán here from the Fin technical support team 👋

I’m going to create a conversation with our support team so they can take a closer look and discuss this further with you. Keep an eye out for a follow-up from the team shortly


We always love hearing what our customers want, and a great place to share feedback like this is our Community Product Wishlist. I'd recommend searching there first to see if a similar request already exists, and if it does you can upvote it or add your comments. If not, you can create a new one here: Product Wishlist.


Forum|alt.badge.img

We second this request. It seems to me that governing changes to FIN AI is quite complex and hinges on each department having their own workspace which - in turn - creates a host of other challenges. Additionally, we experience the following challenges:

Permissions cannot be scoped to a department. Fin permissions are all-or-nothing across the workspace: letting someone edit their own department's setup necessarily lets them edit everyone else's. Separation is therefore policy, naming and review — not something the system enforces. 

Changes to Fin's behaviour are not fully logged. Intercom's audit log covers permissions and logins but records nothing about changes to guidance or escalation rules. An automated "who changed Fin" alert is not possible; detection is a scheduled human review.

Some configurations cannot be rolled back at all. Escalation rules, audiences, attributes, and snippets have no version history. If one is deleted it must be rebuilt from our own written record.

The API bypasses all of the above. Articles, snippets and audiences can be changed or deleted through Intercom's API, invisibly to both logs.

There is no test environment. Intercom's test workspaces do not run Fin's AI answering, so changes cannot be rehearsed against a copy of production. We compensate with a standing set of regression tests.

Let me know if I’ve mistunderstood or am missing information on what FIN offers in this regard.

Thank you.