They break at enforcement. A spreadsheet can describe conflicting duties, but it cannot stop conflicting entitlements from accumulating across apps, delegated admins, and exceptions. Without live linkage to certification, provisioning, and logging, the organisation may pass reviews while still allowing one identity to hold incompatible powers in production.
Why Spreadsheet-Only SoD Breaks at Enforcement
A spreadsheet can document toxic combinations, but it cannot enforce them where access is actually granted. Once duties are spread across SaaS apps, delegated admins, and exception paths, the control becomes informational instead of preventative. The organisation may look governed on paper while the effective access model keeps drifting in production.
The deeper failure is that SoD is not just a policy artifact, it is an access decision that must survive provisioning, role changes, and emergency access. If the control is not wired into the systems that create, review, and log access, the spreadsheet becomes a reference file rather than a living control.
That is why spreadsheet-only SoD often misses the moment where conflicting entitlements accumulate. The conflict can be visible to reviewers and still remain technically possible in the application, which means the business can satisfy audit questions without reducing real privilege overlap.
Where Spreadsheet SoD Usually Fails in the Control Stack
SoD matrices usually fail at the boundaries between ownership, provisioning, and evidence. One team may maintain the matrix, another team may grant access, and a third may review activity after the fact, which leaves no single control point preventing an incompatible combination from being assigned.
Live control requires linkage to identity lifecycle, access certification, and audit logging. Without that linkage, the matrix cannot see delegated administrators, temporary exceptions, or inherited permissions, and those are the exact paths where conflicting power tends to accumulate.
- Provisioning can create conflicts faster than a spreadsheet review cycle can catch them.
- Exceptions can outlive their justification if they are not tied to expiry and reapproval.
- Logging can show that access was used, but not that the access path should never have existed.
A useful way to think about it is that the spreadsheet describes SoD intent, while the runtime control model enforces SoD state. If those two layers are separated, the organisation must rely on manual discipline to keep a preventive control working, and that rarely scales across multiple applications.
What Practitioners Should Expect Instead of Manual SoD Maintenance
Practitioners should expect SoD to behave like a governed entitlement rule, not a static policy chart. The practical question is whether a conflict can be blocked or at least surfaced before it is granted, not whether it can be explained later in a review meeting.
For teams operating across many applications, the best test is whether SoD rules are evaluated during provisioning and recertification with the same identity source of truth. If the control only exists in a spreadsheet, then every new app, role, or delegated admin path becomes a separate manual reconciliation problem.
Segregation of Duties (SoD) Guide is the right next step when you need to move from conflict definitions to enforceable rules, mitigations, and exception handling across both human and non-human access paths.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-5 — Separation of Duties | Directly governs conflicting duties and enforcement of incompatible access paths. |
| AC-6 — Least Privilege | SoD failures often leave users with more privilege than their role should allow. | |
| AU-2 — Event Logging | Audit logging is needed to detect when SoD conflicts are exercised or bypassed. | |
| Recommendation — Enforce AC-5 in provisioning and review workflows so conflicting duties cannot be assigned unchecked. Apply AC-6 to remove excess access that creates toxic duty combinations. Log privileged and exception-based access events so SoD breaches are visible. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | SoD matrices are an access-control mechanism and must be enforced operationally. |
| A.5.18 — Access rights | Rights review and revocation are central to preventing lingering SoD conflicts. | |
| Recommendation — Translate access-control policy into enforced entitlement rules and reviews. Review and revoke access rights that create incompatible duty combinations. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | CIS access management covers lifecycle controls needed to prevent entitlement drift. |
| Recommendation — Implement access control management so SoD rules are enforced in the identity lifecycle. | ||
Practitioner Guidance
What to verify: Check whether the SoD rule set is connected to provisioning, certification, and logging, and whether exceptions carry expiry and accountable ownership. If those links are missing, the matrix is advisory only.
What to prioritise: Focus first on the high-impact conflicting combinations that can create direct financial, operational, or administrative abuse, then extend coverage to delegated admins and emergency access. Those are usually the fastest routes from policy to real exposure.
Common mistake: Treating clean audit narratives as proof of enforcement. A spreadsheet can help demonstrate governance, but it cannot prove that conflicting entitlements were technically prevented from being assigned or retained.
Practitioner takeaway: SoD only works when the control lives in the entitlement lifecycle, not when it is stored as a reference list that people must remember to follow.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org