TL;DR: Traditional segregation of duties breaks down when AI agents, scripts, APIs and cloud services can request, approve and execute financially material actions outside human-paced checkpoints, according to Gathid. The control problem is no longer just who has access, but whether ownership, lifecycle and privilege chains can still be proven in a machine-driven workflow.
Editorial analysis by NHI Mgmt Group, based on content published by Gathid: “The New Segregation Of Duties”.
Key questions
Q: What breaks when segregation of duties is not enforced in identity governance?
A: When segregation of duties is absent, a single identity can create, approve, and audit the same sensitive action.
Q: Why do machine identities create so much SoD risk in finance workflows?
A: They create risk because they can scale quickly, inherit permissions from automation and operate without the visibility that human managers rely on.
Q: How do security teams know if SoD controls are actually working?
A: SoD controls are working only if live access state matches the approved separation model across systems.
Practitioner guidance
- Map financial workflows to identity chains Trace where humans, bots, scripts, APIs and cloud services each request, approve and execute material actions so SoD boundaries reflect actual workflow paths.
- Assign named ownership to every machine identity Require a business owner, purpose statement and renewal cycle for each non-human identity that can touch finance, procurement or production data.
- Timebox and monitor exceptions Replace open-ended SoD exceptions with visible, time-limited approvals and alert on any machine identity that retains conflicting privileges beyond the approved window.
Bottom line: Hybrid SoD fails when machines can participate in the same request, approval and execution chain that older controls assumed would stay human.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Segregation of duties is becoming an identity lineage problem, not just a permissions problem. Classical SoD was designed for human-paced workflows with visible handoffs and stable roles. Once AI agents, scripts and APIs participate in the same business process, the control question shifts to whether the full privilege chain can be proven at any moment. The practitioner implication is that SoD design now belongs in identity governance, not only finance policy.
A question worth separating out:
Q: What should organisations do when automation spans conflicting control surfaces?
A: They should treat the workflow as a control design problem, not just an access problem. If one identity can create, approve and execute across the same business process, the organisation needs to split duties across separate identities, define ownership for each non-human identity and narrow the privileges tied to each step.
👉 Read our full editorial: Rethinking segregation of duties for hybrid human-machine work