Skip to content
IT Canvass
Core concepts · Lesson

Separation of duties

Quick answer

Separation of duties (SoD) is a policy that flags or blocks conflicting access, for example the same person who can create a vendor also being able to approve payments to it. IdentityIQ evaluates SoD policies during requests and identity refresh, and surfaces violations for remediation.

Key takeaways

  • SoD prevents one person holding conflicting access
  • Policies define pairs or sets of conflicting entitlements/roles
  • Evaluated at request time and during identity refresh
  • Violations are remediated or granted a documented exception
  • A core control for SOX and financial compliance

Separation of duties (SoD) is the control that prevents any single person from holding a combination of access that would let them commit and conceal fraud or error, for example both creating a vendor and paying it. It is the control auditors scrutinise most, especially under SOX, and one of the highest-value things SailPoint enforces.

What SoD prevents

Certain pairs of capabilities are dangerous in one pair of hands. SoD policies define these toxic combinations so that no identity can hold both sides, breaking the chain that makes undetected fraud possible.

How SailPoint enforces SoD

  • Policies define conflicting sets of entitlements or roles.
  • At request time, a conflicting request is prevented or requires an explicit, documented exception.
  • During identity refresh, existing violations are detected and raised for remediation.
  • Certifications surface violations for review.

Prevention versus detection

The strongest posture prevents conflicts at request time rather than only detecting them afterward. Where prevention is not possible, violations must be remediated or granted a time-bound, approved exception, and that exception trail is itself audit evidence.

Getting SoD right

SoD quality depends on a well-modelled entitlement set and a ruleset that captures the conflicts that actually matter in your business, particularly in finance systems like SAP. Invest there; vague rules produce noise, precise ones produce control.

Common pitfalls

  • Detect-only SoD with no remediation.
  • Rules over poorly-modelled entitlements, producing noise.
  • No exception process, forcing all-or-nothing outcomes.

Want to learn this properly?

Our live, instructor-led SailPoint Training covers this hands-on, with real projects and a certification path.

Check your understanding

  1. Separation of duties prevents?

    • A. Conflicting access in one person. SoD blocks toxic combinations such as create-and-approve.
    • B. Preventive enforcement. Preventive SoD stops the violating grant up front.
    • C. Documented exception. Exceptions (mitigations) are documented and time-boxed.
    Show answer

    A. Conflicting access in one person. SoD blocks toxic combinations such as create-and-approve.

    Conflicting access in one person. SoD blocks toxic combinations such as create-and-approve.

  2. Blocking a request before access is granted is?

    • A. Documented exception. Exceptions (mitigations) are documented and time-boxed.
    • B. Conflicting access in one person. SoD blocks toxic combinations such as create-and-approve.
    • C. Preventive enforcement. Preventive SoD stops the violating grant up front.
    Show answer

    C. Preventive enforcement. Preventive SoD stops the violating grant up front.

    Preventive enforcement. Preventive SoD stops the violating grant up front.

  3. When conflicting access is genuinely needed, you record a?

    • A. Conflicting access in one person. SoD blocks toxic combinations such as create-and-approve.
    • B. Documented exception. Exceptions (mitigations) are documented and time-boxed.
    • C. Preventive enforcement. Preventive SoD stops the violating grant up front.
    Show answer

    B. Documented exception. Exceptions (mitigations) are documented and time-boxed.

    Documented exception. Exceptions (mitigations) are documented and time-boxed.

Frequently asked questions

What does the term separation of duties (SoD) refer to in SailPoint?

Separation of duties (SoD) is the control that prevents any single person from holding a combination of access that would let them commit and conceal fraud or error, for example both creating a vendor and paying it.

What do auditors expect from separation of duties (SoD)?

Where prevention is not possible, violations must be remediated or granted a time-bound, approved exception, and that exception trail is itself audit evidence.

What is the practical takeaway on separation of duties (SoD)?

Certain pairs of capabilities are dangerous in one pair of hands.

What tends to go wrong with separation of duties (SoD)?

Detect-only SoD with no remediation. Rules over poorly-modelled entitlements, producing noise. No exception process, forcing all-or-nothing outcomes.
CallWhatsAppEnquire