Segregation of Duties

Find the Access Conflicts Hidden Inside Entitlements

Identify the exact applications, roles, groups, credentials, and entitlements creating Segregation of Duties conflicts.

Bring conflicting access into governed requests, reviews, remediation, and reporting so teams can understand what created the risk, decide what should change, and verify that the change actually happened.

SoD Conflict
Entitlement-level detection
3 open
Create Vendor + Approve Payment
ERP · Cross-function conflict
Conflict
Admin + Auditor Role
Finance App · Same identity
Review
AP Clerk + Bank Transfer
Core banking · Dual control break
Revoke?
Move from “this user has an SoD violation” to the exact access that needs attention.
Entitlement-Level Visibility

See Exactly What Access Created the Conflict

An SoD violation is difficult to resolve when teams can only see that a conflict exists. Bring identities, credentials, roles, groups, and entitlements together to show the specific access responsible for the violation.

Identify the Entitlement

See which entitlement—or combination of entitlements—created the SoD conflict.

Understand the User Context

Connect the conflicting access to the identity, account, application, role, or group holding it.

See Cross-Application Conflicts

Identify combinations that may not be visible when each application is reviewed independently.

Move from “this user has an SoD violation” to “this is the exact access that needs attention.”
One Governed SoD Process

Detect, Review, Remediate, and Prove the Outcome

Bring SoD controls into the access governance processes your team already uses.

01

Identify

Detect conflicting access across identities, roles, groups, credentials, and entitlements.

02

Evaluate

See the specific access creating the conflict and the business context around the user.

03

Review

Route access to managers, application custodians, or entitlement custodians who understand whether the access is required.

04

Remediate

Revoke or adjust access that should no longer remain.

05

Verify

Compare review decisions with refreshed application data to confirm that conflicting access was actually removed.

06

Prove

Retain decisions, approvals, timestamps, tickets, notes, and reporting as evidence of the control.

Prevent Conflicts Earlier

Bring SoD Checks Into Governed Access Requests

SoD controls are more effective when conflicting access can be identified before it becomes another cleanup exercise. Use governed access requests, approval workflows, Access Templates, and controlled provisioning to introduce SoD checks before access is ultimately granted.

Governed Requests

Move application and entitlement requests out of email and manual service desk workflows.

Approval Context

Give approvers clearer visibility into the requested access before making the decision.

Controlled Provisioning

Keep the approval and resulting access change connected within the governance process.

Standardized Access

Use predefined Access Templates to reduce one-off entitlement combinations that are harder to govern.

Explore Access Requests →

Standardized Access Governance

Use Access Templates to Make Conflicting Access Easier to Control

Access Templates group approved applications and entitlements into repeatable access packages. Standardizing common access makes it easier to understand what users are expected to receive—and identify access that falls outside the approved model.

Access Template Composition Reviews

Periodically review the applications and entitlements included inside each Access Template. This helps owners confirm that standardized access remains appropriate as applications, responsibilities, and business requirements change.

Access Template Membership Reviews

Review which users are assigned to a specific Access Template. This helps ensure that sensitive or higher-risk combinations of access remain limited to the people who require them.

Outlier Reviews

Identify entitlements users hold outside their assigned Access Template. Highlight exceptions, privilege creep, and additional access that may introduce new SoD risk.

User Access Reviews

Put SoD Decisions in Front of the People Who Understand the Access

Detecting a conflict is only useful if the right person can decide whether the access should remain. Bring SoD concerns into entitlement-level access reviews so managers, application custodians, and entitlement custodians can evaluate the business need behind the access.

Manager Reviews

Let managers evaluate whether access still aligns with the user's responsibilities.

Application Custodian Reviews

Route application-specific access to owners who understand how that system is used.

Entitlement Custodian Reviews

Give entitlement owners visibility into the individual permissions creating the conflict.

Approve or Revoke

Keep the decision connected to the exact entitlement under review.

Explore User Access Reviews →

Reviewer queue
SoD conflict items
8 remaining
J. Patel · Create + Approve
ERP · Entitlement custodian review
Decide
A. Morales · Admin role
Finance App · Manager review
Keep
svc_ap_01 · Wire initiate
Core banking · Owner assigned
Review
Review conflicting access, capture comments, and decide without leaving the campaign.
Remediation Effectiveness

A Revoke Decision Is Not Enough Until the Access Is Gone

An SoD control is not complete when a reviewer clicks revoke. Campaign Effectiveness reporting compares review decisions with refreshed application data so teams can confirm that access marked for removal was actually remediated.

Review the Decision

See which entitlement or conflicting access was marked for revocation.

Refresh Application Data

Bring updated access information back from the source application.

Compare the Result

Determine whether the conflicting access still exists after the remediation action.

Confirm Closure

Keep evidence that the requested change was actually completed.

Prove the difference between deciding to revoke access and actually removing it.
Audit Evidence

Show How the SoD Conflict Was Identified, Reviewed, and Resolved

Audit evidence should show the full control history—not just the final status. Keep the information required to demonstrate how conflicting access was handled from identification through remediation.

Audit-Ready Record

  • User and account details
  • Applications and entitlements
  • SoD conflict details
  • Approval history
  • Reviewer decisions
  • Notes and business context
  • Timestamps
  • Ticket information
  • Remediation status
  • Campaign Effectiveness results
Campaign evidence
Q3 SoD Control Review
Complete
Conflicts identified
64 conflicts · entitlement detail retained
Complete
Revocations
19 marked · remediation tracked
Tracked
Effectiveness check
Refreshed data confirms removals
Evidence
This gives audit and compliance teams a clearer record of what created the conflict, who evaluated it, what decision was made, and whether the access was ultimately corrected.
Connected Access Governance

Make SoD Part of the Broader Identity Governance Program

Segregation of Duties works best when it is connected to the processes that create, review, and remove access.

Access Requests

Identify potential conflicts as users request additional applications or entitlements.

Explore Access Requests →

User Access Reviews

Put existing conflicting access in front of accountable reviewers.

Explore User Access Reviews →

Access Analysis

Find excessive, dormant, unusual, and risky access that may require further investigation.

Explore Access Analysis →

Identity Governance & Administration

Connect SoD controls with lifecycle management, provisioning, access requests, reviews, and broader identity governance.

Explore Identity Governance →

FAQ

Segregation of Duties FAQs

What Is Segregation of Duties?

Segregation of Duties separates access or responsibilities that should not be controlled by the same person. In identity governance, SoD controls help identify combinations of permissions that may create security, financial, operational, or compliance risk.

How Are SoD Conflicts Identified?

Conflicting access can be evaluated across identities, credentials, roles, groups, applications, and individual entitlements. Entitlement-level visibility helps teams understand the specific access creating the violation.

Can SoD Conflicts Span Multiple Applications?

Yes. Conflicting access may exist across different applications and systems. Bringing access information together makes it possible to identify combinations that may not be visible when applications are reviewed independently.

Can SoD Checks Be Used During Access Requests?

Governed access requests, approval workflows, Access Templates, and controlled provisioning provide an opportunity to evaluate potentially conflicting access before the requested permissions are ultimately granted.

What Are Access Template Composition Reviews?

Access Template Composition Reviews allow owners to periodically evaluate the applications and entitlements included within a predefined Access Template and confirm that the package remains appropriate.

What Are Access Template Membership Reviews?

Membership Reviews validate which users are assigned to an Access Template, helping organizations determine whether standardized or sensitive access remains limited to the appropriate people.

What Is an Outlier Review?

An Outlier Review identifies access a user holds outside their assigned Access Template. This can highlight exceptions, privilege creep, and additional entitlements that may introduce SoD risk.

How Can Teams Verify That Conflicting Access Was Removed?

Campaign Effectiveness reporting compares access review decisions with refreshed application data, helping teams confirm whether entitlements marked for revocation were actually removed.

See How SoD Fits Your Access Governance Program

Find conflicting access, put decisions in front of the right owners, verify remediation, and keep the evidence needed to prove the control worked.