Separation of duties fails when different agents can combine partial privileges to complete a sensitive action that no single agent should be able to perform. One identity may create the object and another may authorize it, which looks compliant in isolation but violates policy in combination. Governance must evaluate the workflow, not just each agent separately.
How separation of duties breaks in collaborative agent workflows
Separation of duties breaks when the workflow, not the individual agent, is the unit of authority. If one agent can create, prepare, or queue an action and another can approve, release, or execute it without a truly independent policy check, the system can satisfy each step in isolation while still enabling a sensitive end state. That is a governance failure, not just a permissions issue.
In collaborative workflows, the dangerous pattern is cumulative authority. A creator agent may not be able to approve its own output, but it can hand off a precondition that makes the next agent’s approval effectively rubber-stamped. This is especially common when shared context, delegated tokens, or weak approval gates let agents rely on each other’s assumptions instead of on an external control boundary.
The practical test is whether any one workflow path can reach an action that should require independent human or policy separation. If the same principal set, orchestration layer, or shared identity fabric can complete the transaction, SoD is only appearing to hold. For a broader identity baseline, IAM and IGA Basics is the right foundation for understanding why entitlement design and access review must follow the workflow, not just the account list.
SoD also fails when the system treats partial privileges as harmless. One agent may have object creation rights, another may have approval rights, and a third may have execution rights, yet the combination can still be toxic if those steps are meant to be mutually exclusive. That is why SoD rulesets have to account for chained operations, not just single permissions. The Segregation of Duties (SoD) Guide is directly relevant here because it addresses toxic combinations, mitigations, and extension of SoD to bots and AI agents.
In agentic systems, the failure mode gets worse when delegation is implicit. A task-scoped agent can still become a policy bypass if it inherits standing access, reuses a privileged session, or is allowed to pass work to another agent without fresh authorization. The right control question is not “did two different agents touch it?” but “did two independently governed decisions exist, with no shared privilege path that collapses the separation?” For that reason, AI Agent Authorisation Guide is a strong companion because it focuses on per-action policy decisions and delegated authority.
Well-run workflows make the SoD boundary explicit. Creation, review, approval, and execution should be distinct decision points with traceable ownership, and no single agent chain should be able to satisfy them all through context reuse or hidden privilege inheritance. If the workflow can be replayed, automated, or recombined after the fact, then the separation must be enforced at the policy layer, not inferred from the presence of multiple actors.
Risk and Threat Considerations
When SoD fails in agent workflows, the main risk is false assurance: audit logs may show multiple participants even though the same effective trust path enabled the action. That creates fraud, abuse, and change-control exposure, especially where one agent prepares a request and another approves it using the first agent’s assumptions or artifacts.
Failure mechanism: The workflow distributes steps across agents, but the underlying authority is still composable, so a privileged outcome can be assembled from partial rights, shared state, or delegated credentials.
Impact: Sensitive actions can be approved or executed without genuine independence, making unauthorized changes, policy bypass, and difficult-to-detect abuse much more likely.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 and OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Collaborative agents can combine partial privileges into one sensitive outcome. |
| Recommendation — Enforce independent per-action authorization so agents cannot assemble a forbidden outcome from split duties. | ||
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Split workflow roles still fail if the underlying non-human principals retain excess privilege. |
| Recommendation — Remove standing privilege that lets multiple agents combine access into one unauthorized transaction. | ||
| NIST SP 800-53 Rev 5 | AC-5 — Separation of Duties | The question is fundamentally about workflow-level duty separation and toxic combinations. |
| AC-6 — Least Privilege | Partial privileges become risky when they can be composed into a sensitive action. | |
| IA-5 — Authenticator Management | Shared or reusable credentials can collapse the distinction between separate agent duties. | |
| Recommendation — Define separation rules across the full workflow and block conflicting role combinations. Reduce each agent to the minimum privilege needed for its single workflow step. Rotate and bound credentials so one agent cannot reuse another’s access path. | ||
Practitioner Guidance
What to verify: Check whether each workflow step has an independent authorizing principal, not just a different automated actor. If creation and approval can be performed within the same trust chain, treat the design as SoD-weak even if the UI shows separate reviewers.
Decision rule: If two agents can combine partial privileges to complete the same sensitive transaction, redesign the policy boundary before tuning monitoring or adding review alerts. The control objective is to prevent the combination, not merely to detect it after the fact.
What good looks like: A compliant workflow forces a separate policy decision at the point of approval or execution, with no reusable privilege path that an upstream agent can precompute for the downstream one.
Practitioner takeaway: In collaborative agent systems, SoD is only real when the control prevents privilege composition across the whole workflow, not when it merely assigns different labels to different steps.