Multisignature, usually shortened to multisig, requires signatures from multiple keys to satisfy a spending policy. BIP 16 includes a 2-of-3 example: any two of three specified keys can authorize the spend, provided the rest of the transaction is valid. The P2SH example.

What 2-of-3 means

In this simplified example, all three keys are distinct and the wallet configuration is available:

Usable signing keys Enough to satisfy the signature threshold?
One No
Two Yes
Three Yes; two are sufficient

It is the signatures that must meet the rule. Three labels in an app do not demonstrate that three secrets are independently controlled. Conversely, a multisig arrangement can involve several devices operated by the same person.

Moving a transaction between signers

A partially signed Bitcoin transaction, or PSBT, is a format for sharing transaction information and collecting signatures. It supports workflows where signers do not have direct network access. Signing and broadcasting remain different steps, and a PSBT file is not evidence that the transaction has been confirmed. BIP 174.

Recovery needs the policy too

Reconstructing a multisig wallet can require its participating public keys, script structure, derivation information, and threshold—not just enough individual secret backups. Descriptors provide a way to express output scripts and key information. BIP 380.

This is why “I saved two sets of words” does not, by itself, establish that a complete recovery has been planned.

A different set of trade-offs

Separating signers can reduce dependence on one device or location. It also introduces coordination and backup responsibilities. If enough keys are compromised together, the threshold can still be met; if too many become unavailable, legitimate spending may become impossible. The security guide’s multisignature discussion.

For the underlying distinction between backups and keys, read recovery phrases and wallet backups.