By NHI Mgmt Group Editorial TeamBased on SecurEnds: “Entitlement management: What Are Toxic Combinations in SoD?” (June 29, 2026)

TL;DR: Toxic combinations in segregation of duties let one user complete incompatible business actions such as creating and approving payments, increasing fraud, error, and compliance risk across ERP, cloud, and finance workflows, according to SecurEnds. The control problem is not merely access volume but role design, exception handling, and review cadence.


At a glance

What this is: This is an analysis of why toxic SoD conflicts remain a governance problem even when organisations already have access controls in place.

Why it matters: It matters because IAM, IGA, PAM, and GRC teams have to govern incompatible business permissions as a process risk, not only as an entitlement count.


Context

Segregation of duties is the control principle that keeps one person from controlling incompatible steps in a sensitive business process. The problem arises when users accumulate conflicting permissions across ERP, finance, cloud, and enterprise applications, creating toxic access combinations that bypass oversight.

In modern identity governance programmes, SoD is not just an audit checkbox. It is a control design issue, a role engineering issue, and a review cadence issue. Once exceptions, emergency access, and manual provisioning enter the picture, toxic combinations can persist even when access reviews exist.


Key questions

Q: What breaks when one person can create and approve the same financial transaction?

A: The control stops detecting fraud and errors because the same identity can introduce, authorise, and conceal an entry. That breaks audit traceability, weakens accountability, and creates a single point of failure in ERP workflows. In SOX terms, it turns a control into a compliance liability.

Q: Should organisations prioritise remediation over mitigation for SoD conflicts?

A: Yes, remediation should come first whenever access can be removed without disrupting essential operations. Mitigation is for the remainder, where business necessity creates a defensible exception. The key is not to use mitigation as a shortcut, because accepted conflicts still need review, monitoring, and renewal.

Q: How do security teams know if SoD controls are actually working?

A: SoD controls are working only if live access state matches the approved separation model across systems. Teams should verify that no identity can both initiate and validate the same sensitive transaction, and that exceptions are time-bound and independently reviewed. If certification reports look clean but operational workflows still allow self-approval, the control is failing.

Q: What is the difference between segregation of duties and toxic combinations?

A: Segregation of duties is the control principle that separates incompatible responsibilities. Toxic combinations are the actual access states that violate that principle, such as a user who can both create and approve the same financial action. One is the design rule, the other is the control failure.


Technical breakdown

How toxic access combinations form in role-based environments

Toxic combinations usually emerge when business roles are assembled from multiple application entitlements without modelling the process conflict behind them. A user may receive separate permissions to create vendors, approve payments, post journal entries, or administer accounts, and those permissions become dangerous when combined. The technical issue is not that each entitlement is excessive in isolation, but that the combination collapses the control boundary between initiation and approval. In ERP and finance systems, that boundary is what preserves accountability and prevents self-approval.

Practical implication: model SoD at the business-process level, not only at the role or application level.

Why entitlement drift creates persistent SoD violations

Entitlement drift happens when users collect extra access through job changes, emergency access, mergers, or manual provisioning mistakes. Over time, those additions create permission sets that no longer match the intended control model. Because SoD rules are often checked only periodically, a conflict can exist for months before it is detected. In practice, this means the governance problem is temporal as well as structural: even clean role design can fail if access lifecycle controls do not remove obsolete permissions quickly enough.

Practical implication: connect role changes, temporary access, and recertification so drift is removed before it becomes a standing conflict.

How continuous SoD analysis maps technical access to business risk

Continuous SoD analysis translates entitlements into business activities and checks whether any user can complete incompatible steps without independent review. That requires rule sets that understand both the technical permission and the operational meaning of the action. For example, two harmless-looking entitlements can become a fraud path if they allow the same person to create and approve the same transaction flow. The value of continuous analysis is that it reveals emerging conflicts as systems, roles, and workflows change, rather than waiting for a manual audit to discover them.

Practical implication: use continuous entitlement intelligence to detect new conflicts as workflows and roles evolve.


Threat narrative

Attacker objective: The objective is to complete incompatible business actions without independent oversight so transactions, records, or approvals can be manipulated.

  1. Entry occurs when a user receives or accumulates conflicting permissions through role design, emergency access, mergers, or manual provisioning.
  2. Escalation follows when that user can initiate and approve the same business process, bypassing the separation that should force independent review.
  3. Impact is realised through fraudulent transactions, hidden accounting changes, operational abuse, or compliance failures that are harder to detect and harder to unwind.

Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.


NHI Mgmt Group analysis

SoD conflicts are a process-governance failure, not an access-volume problem. The article shows that a user can hold individually legitimate entitlements and still violate control intent when those permissions combine inside one workflow. That is why entitlement count alone is a poor signal for governance maturity. The real question is whether the role model preserves independent review across business steps.

Role accumulation is the governance debt hidden inside mature environments. Emergency access, organisational change, and manual provisioning all create drift that static role design cannot absorb on its own. Once a conflict becomes embedded in a role or exception, it behaves like standing privilege for a business process. The implication is that SoD must be governed as lifecycle control, not only as policy design.

Continuous SoD monitoring is now part of identity assurance. Modern finance, ERP, and cloud workflows change too quickly for periodic spreadsheet review to remain sufficient. Continuous entitlement intelligence gives GRC teams the signal needed to detect incompatible combinations before they harden into audit findings. The practitioner takeaway is that SoD quality should be measured in near-real time, not only at recertification.

Toxic access combinations expose the limits of exception-heavy governance. Compensating controls can reduce risk when conflicts cannot be removed immediately, but they do not restore the original control boundary. If the same user can create and approve the same transaction, the programme is already operating on trust rather than separation. Practitioners should treat each exception as evidence of control-design debt that must be reduced over time.

SOX, ISO 27001, SOC 2, and PCI DSS all converge on the same governance expectation. The article correctly frames SoD as a cross-framework control issue because incompatible duties weaken accountability regardless of platform. That means identity, finance, and audit teams need one shared conflict model, not separate interpretations of the same access state. Practitioners should align SoD rules with the business process they actually govern.

What this signals

Toxic access combinations are usually a role-engineering problem before they become a fraud problem. Once permissions are bundled into business roles without process-aware separation, the control weakness is already built into the operating model. For IAM and IGA teams, that means SoD has to be reviewed where roles are designed, not only where audits are run.

Exception-heavy governance creates hidden standing privilege. Emergency access and compensating controls are often necessary, but they become dangerous when they persist beyond the event they were meant to cover. Practitioners should treat every long-lived exception as a sign that lifecycle controls are not enforcing the intended boundary.

SoD quality depends on continuous visibility into entitlement combinations. Static review cycles miss conflicts that appear when systems, roles, and workflows change between audits. The practical shift is toward automated entitlement intelligence that can detect incompatible access as soon as it is introduced.


For practitioners

  • Define SoD at the business-process layer Map incompatible steps such as create, approve, post, and pay before translating them into entitlement rules. Process-first modelling prevents harmless-looking permissions from hiding toxic combinations.
  • Track access drift as a lifecycle problem Review emergency access, mergers, job changes, and manual provisioning together so obsolete permissions do not persist as hidden SoD violations.
  • Automate continuous conflict detection Run entitlement analysis against SoD rules continuously across ERP, finance, and cloud applications instead of waiting for periodic review cycles.
  • Document and age every exception Treat compensating controls as temporary governance debt, with explicit ownership, expiry, and follow-up until the underlying conflict is removed.

Key takeaways

  • Toxic segregation of duties conflicts show that access governance can fail even when individual permissions look valid on their own.
  • The article highlights that conflicts often emerge through role accumulation, emergency access, manual provisioning, and system consolidation.
  • The most effective control response is to model incompatible business steps directly and remove recurring conflicts instead of relying on exceptions alone.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST SP 800-53 Rev 5AC-6 — Least PrivilegeSoD conflicts arise when users accumulate access beyond what their duties require.
Recommendation — Apply AC-6 to remove permissions that let one user complete incompatible business steps.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsSoD monitoring is part of controlling and reviewing entitlements across workflows.
Recommendation — Use PR.AA-05 to govern entitlement combinations that create toxic access states.
CIS Controls v8CIS-5 — Account ManagementAccount lifecycle and role changes are a common source of SoD drift and conflicting access.
Recommendation — Use CIS-5 to review account changes and remove conflicting access when duties change.
ISO/IEC 27001:2022A.5.15 — Access ControlAccess control in ISO 27001 covers the governance expectation behind SoD separation.
Recommendation — Apply A.5.15 to define and enforce incompatible access boundaries across business processes.
SOC 2 (AICPA)CC6.1 — Logical and Physical Access ControlsSoD conflicts expose weaknesses in access governance and internal control evidence.
Recommendation — Use CC6.1 to prove that access is restricted so one user cannot control incompatible actions.

Key terms

  • Segregation of Duties: Segregation of Duties is a control principle that prevents one person or role from combining incompatible permissions that could create fraud, error, or undetected change. In ERP environments, it must account for roles, transactions, approvals, and compensating controls across business processes.
  • Toxic Risk Combinations: Toxic risk combinations are unsafe interactions between datasets, access permissions, and AI workflows that only become problematic when combined. Individually they may appear harmless, but together they can expose sensitive information, enable re-identification, or create unintended inferences that traditional controls may miss.
  • Compensating Control: A compensating control is a measure that reduces risk when the ideal fix, such as immediate patching or redesign, is not possible. In OT, compensating controls often include session recording, access restriction, and tighter monitoring. They do not eliminate the underlying issue, but they narrow exposure until safer remediation can happen.
  • Entitlement Drift: Entitlement drift is the slow accumulation of permissions that no longer match the original purpose, role, or workload. In cloud-native and NHI-heavy environments, it usually happens because access changes faster than review cycles, leaving organizations with more privilege than they intended.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or NHI governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 6, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org