What is Castle
Castle is Station70's modern, multi-factor management platform. It allows organizations to centrally manage and share time-based one-time passwords (TOTP codes) with teams — with full control over who can access what, and when.
The problem Castle solves
Shared TOTP codes are a common headache for enterprise teams. When multiple people need access to the same 2FA-protected account, organizations typically resort to screenshots, shared password managers, or re-enrollment across devices, all of which create security gaps and operational friction.
Castle eliminates this by giving enterprises a central place to register TOTP credentials and distribute real-time access to member, with policy controls that enforce approval workflows where needed.
Key Concepts
| Term | What it means |
|---|---|
| Resource | A single TOTP credential — e.g. the 2FA code for a specific platform or account. Each resource has its own access settings. |
| Access Control |
The access rules for a resource. By default, a resource is only available to the member that created it. However, access can be shared with any combination of members or groups. Also, resources are instantly-accessible to to all members of the access list unless an approval has been required. |
| Group | A collection of members that can be assigned access or approve access to resources. |
| Approver | Members or groups designated to approve or deny access requests under an approval-required resource. |
Who Does What?
| Account Admin | Member |
|---|---|
|
|
How Access Works
Each resource has one of two access modes:
Instant access
- Any member assigned to the resource sees the live TOTP code immediately in the mobile app, no approval needed.
Approval-required (just-in-time)
- The member submits a request, and one or more designated approvers must approve before the code is available.