What is Castle

Castle is Station70's modern, multi-factor management platform. It allows organizations to centrally manage and share time-based one-time passwords (TOTP codes) with teams — with full control over who can access what, and when.

The problem Castle solves

Shared TOTP codes are a common headache for enterprise teams. When multiple people need access to the same 2FA-protected account, organizations typically resort to screenshots, shared password managers, or re-enrollment across devices, all of which create security gaps and operational friction.

Castle eliminates this by giving enterprises a central place to register TOTP credentials and distribute real-time access to member, with policy controls that enforce approval workflows where needed.

Key Concepts

Term What it means
Resource A single TOTP credential — e.g. the 2FA code for a specific platform or account. Each resource has its own access settings.
Access Control

The access rules for a resource. By default, a resource is only available to the member that created it. However, access can be shared with any combination of members or groups.

Also, resources are instantly-accessible to to all members of the access list unless an approval has been required.

Group A collection of members that can be assigned access or approve access to resources.
Approver Members or groups designated to approve or deny access requests under an approval-required resource.

Who Does What?

Account Admin Member
  • Accesses the web console at app.castle.station70.com
  • Creates and manages member and groups
  • Configures access policies per resource
  • Creates resources and set the initial sharing options
  • Edits personal (not shared) resources
  • Requests or instantly views TOTP codes for resources they have access to
  • Cannot modify members, groups, or access control for shared resources

How Access Works

Each resource has one of two access modes:

Instant access

  • Any member assigned to the resource sees the live TOTP code immediately in the mobile app, no approval needed.

Approval-required (just-in-time)

  • The member submits a request, and one or more designated approvers must approve before the  code is available.