Terminology Index

Glossary

1 term tagged "segregation-of-duties-modeling"

Open concept maps

Showing 1-1 of 1 term

S
1

Segregation of Duties Modeling

Modeling segregation-of-duties (SoD) constraints in IGA, identifying which combinations of access shouldn't be held by the same person, so the access model enforces SoD rather than relying on after-the-fact review.

Segregation of duties prevents one person from holding combinations of access that enable fraud or error (e.g., requesting and approving the same payment). SoD modeling in IGA captures these constraints as policy: defined conflicting role pairs or entitlement combinations the system blocks at provisioning and flags during reviews. Done well, SoD is enforced by design rather than discovered in audits. It is an IGA practice closely tied to access certification and audit-driven risk reduction.

Introduced in: Identity Governance and Administration

Examples

  • Defining conflicting role pairs the IGA system blocks at provisioning.
  • Flagging SoD violations during access certification reviews.
  • Enforcing SoD by design rather than discovering violations later.

No related terms linked yet.