They should treat them as linked, but identity lifecycle often exposes the deeper failure because access changes must flow through SAP and all connected systems. If joiner, mover, and leaver events are not governed end to end, SoD findings will recur and certifications will remain evidentially weak.
Why SAP SoD and identity lifecycle governance should not be treated as separate queues
SAP segregation of duties is usually the visible control because it flags toxic combinations inside the ERP. identity lifecycle governance is the control plane underneath it, because joiner, mover, and leaver events decide who can keep, gain, or lose access across SAP and connected systems. If lifecycle governance is weak, SoD exceptions keep reappearing even after cleanup.
The practical priority is to treat SoD as a policy outcome and lifecycle governance as the operating mechanism. SoD tells you which access combinations are unsafe; lifecycle governance tells you whether access changes, removals, and entitlement reviews are happening consistently enough to stop those unsafe combinations from returning.
That is why the question is not really SAP versus identity governance. It is whether the organisation can make SAP access decisions flow from an authoritative joiner, mover, leaver process, with ownership, approvals, and downstream revocation working across every connected application.
Where the deeper control failure usually sits
SoD often exposes symptoms such as conflicting roles, emergency access that never expires, or dormant access left behind after a move or exit. Identity lifecycle governance exposes the root cause when those conditions are created by incomplete provisioning, delayed deprovisioning, unmanaged role inheritance, or poor recertification evidence. A strong SAP control stack still fails if the upstream identity record is stale or the downstream revocation never reaches every system that matters.
In mature environments, the lifecycle question is broader than SAP alone. HR events, role changes, contractor offboarding, and cross-system entitlements must all converge on the same entitlement record or governance workflow. If they do not, the SAP review may be accurate on the day it runs but obsolete by the time auditors or business owners rely on it.
For practitioners who want a control baseline, the most useful starting point is a joiner-mover-leaver model that is tied to access review and entitlement ownership, not a one-off SoD remediation project. NHIMG’s Joiner-Mover-Leaver (JML) Guide is a useful companion for that operating model, and the Segregation of Duties (SoD) Guide shows why conflict prevention and detection need to work together.
What to prioritise first if the goal is fewer repeat SoD findings
If the organisation is still cleaning up repeated SoD violations, prioritise lifecycle governance first, then harden the SAP SoD rule set. That sequence matters because a cleaner entitlement lifecycle reduces the number of conflicting roles that must be managed, investigated, and justified. It also improves the quality of certifications because reviewers are validating current access rather than compensating for stale records.
Start by verifying that joiner, mover, and leaver events are authoritative, timely, and closed loop. Then confirm that every material SAP role change, temporary access grant, and termination action produces a downstream entitlement update in the connected systems that can reintroduce SoD exposure. If a leaver can still authenticate somewhere after SAP access is removed, the control problem has not been solved.
For SAP-specific governance, it is often helpful to separate conflict design from conflict administration. The design work defines which combinations are forbidden; the administration work proves who owns the exception, how long it lasts, and what revocation happens when the business justification ends. NHIMG’s IAM and IGA Basics is useful for the entitlement and recertification side, while the NHI Ownership and Accountability Guide is a strong reminder that every identity needs a clear owner before governance can work reliably.
How to judge whether the control stack is actually improving
The best signal is not the number of findings closed in SAP, but whether repeat findings decline after lifecycle fixes are made. Look for shorter time-to-revoke after mover and leaver events, fewer manual overrides, and fewer certifications that depend on spreadsheet reconciliation. If access changes still require side channels or after-the-fact cleanup, the organisation has governance activity, not governance closure.
Another useful test is whether the business can explain why each exception exists and who owns its expiry. If that answer depends on tribal knowledge, the SoD program is carrying a lifecycle defect. If it is captured in workflow, approval records, and entitlement history, the organisation is much closer to a durable control.
When this pattern is widespread, it is worth reviewing the access model at the entitlement level, not only at the SAP role level. NHIMG’s Ultimate Guide to NHIs, lifecycle processes for managing them is relevant because it shows the broader governance principle: lifecycle discipline, ownership, and revocation are what keep access controls from degrading over time.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-5 — Account Management | SAP SoD depends on timely account lifecycle control and removal of stale access. |
| Recommendation — Enforce account lifecycle controls and remove obsolete access promptly. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Lifecycle governance must rotate and revoke credentials tied to SAP and connected access. |
| AC-2 — Account Management | Joiner, mover, leaver governance depends on provisioning, changes, and deprovisioning. | |
| AC-5 — Separation of Duties | The question directly concerns whether SoD or lifecycle governance should lead. | |
| Recommendation — Manage authenticator lifecycle and revoke stale credentials without delay. Automate account provisioning, modification, and removal from authoritative events. Define SoD conflicts and enforce compensating approvals for risky combinations. | ||
| ISO/IEC 27001:2022 | A.5.16 — Identity management | Identity lifecycle governance underpins controlled access changes and revocation. |
| Recommendation — Operate identity lifecycle processes from joiner through leaver. | ||
Practitioner Guidance
What to prioritise: If repeated SoD findings are the pain point, fix the joiner, mover, leaver process first, because it reduces the number of toxic combinations that SAP governance has to absorb later.
What to verify: Confirm that every access grant, role change, and offboarding event has a documented owner and a verified downstream revocation path, not just an approval in the source system.
Common mistake: Treating SAP role cleanup as a standalone compliance project instead of proof that the identity lifecycle is actually functioning end to end.
Decision rule: If the same SoD conflict keeps reappearing, treat it as a lifecycle and entitlement-control failure before you treat it as a pure SAP configuration issue.
Practitioner takeaway: SoD is usually the exception list, but lifecycle governance is the mechanism that decides whether the exception list shrinks or keeps regenerating.
Related resources from NHI Mgmt Group
- Should organisations prioritise external exposure or internal credential governance first?
- Should organisations prioritise least privilege or lifecycle governance first for AI agents?
- What should organisations prioritise first in identity governance?
- What should organisations prioritise first in identity governance programmes?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org