TL;DR: Segregation of duties prevents one privileged person from creating access, approving changes, and erasing evidence, reducing insider misuse and audit exposure across cloud, SaaS, and data center environments, according to SecurEnds. The control only works when identity governance, role design, and exception handling stay current with real admin workflows.
Editorial analysis by NHI Mgmt Group, based on content published by SecurEnds: “Segregation of Duties in Cybersecurity: Safeguarding Access and Preventing Fraud”.
Key questions
Q: What breaks when one admin can create access and approve it too?
A: The control breaks at the point where access creation, approval, and oversight collapse into one identity.
Q: Why do cloud admin roles make segregation of duties harder to enforce?
A: Cloud platforms often centralise powerful actions into a few broad roles, so one person can accumulate more authority than legacy operating models expected.
Q: How do organisations know whether segregation of duties is actually working?
A: Segregation of duties is working only if no identity can combine enough permissions to complete the full banking workflow without an independent check.
Practitioner guidance
- Define toxic role combinations Map the specific duty pairs that must never sit in one identity, such as requester and approver, builder and reviewer, or admin and audit owner.
- Separate privileged workflow steps Break account creation, privilege assignment, and monitoring into distinct approval paths so one admin cannot complete the full action chain alone.
- Review emergency access exceptions Document every exception to SoD, assign compensating review ownership, and retire exceptions before they become de facto operating practice.
Bottom line: Segregation of duties prevents a single privileged identity from controlling the full admin lifecycle, which is why it remains central to access governance.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Segregation of duties is an access governance control, not a paperwork control. The article is right to frame SoD as a guardrail that limits what a single privileged identity can do end to end. In modern environments, the real risk is not only misuse, but the concentration of authority across provisioning, approval, and oversight. Practitioners should treat role separation as a runtime control over admin power, not a compliance label.
A few things that frame the scale:
- U.S. fraud losses are projected to reach $40 billion by 2027.
A question worth separating out:
Q: When should organisations rely on compensating controls instead of perfect SoD splits?
A: Use compensating controls only when team size or operating model makes a full split impossible, and document the reviewer, frequency, and evidence trail. They are not a substitute for separation, but they can reduce risk where one person must hold more than one function temporarily.
👉 Read our full editorial: Segregation of duties is the control that limits admin abuse