Terminology Index
Glossary
1 term tagged "segregation-of-duties-modeling"
Showing 1-1 of 1 term
Segregation of Duties Modeling
Modeling segregation-of-duties (SoD) constraints in IGA, identifying which combinations of access shouldn't be held by the same person, so the access model enforces SoD rather than relying on after-the-fact review.
Segregation of duties prevents one person from holding combinations of access that enable fraud or error (e.g., requesting and approving the same payment). SoD modeling in IGA captures these constraints as policy: defined conflicting role pairs or entitlement combinations the system blocks at provisioning and flags during reviews. Done well, SoD is enforced by design rather than discovered in audits. It is an IGA practice closely tied to access certification and audit-driven risk reduction.
Introduced in: Identity Governance and Administration
Examples
- Defining conflicting role pairs the IGA system blocks at provisioning.
- Flagging SoD violations during access certification reviews.
- Enforcing SoD by design rather than discovering violations later.
No related terms linked yet.
