When SoD is not enforced across joiner, mover, and leaver stages, conflicting access can persist as roles change. That creates opportunities for unauthorized payments, self granted access, unreviewed administrative actions, and weak audit evidence. Over time, the organisation also loses confidence in its controls because recertification, monitoring, and remediation no longer keep pace with changing responsibilities.
How separation of duties breaks down across the identity lifecycle
Separation of Duties only works when it is enforced as access changes, not just when a role is first approved. Across joiner, mover, and leaver events, conflicting entitlements can accumulate if provisioning, approval, and review are handled as isolated tasks rather than a single control loop. The practical result is role drift: users keep powers that no longer match their current responsibilities.
That matters because SoD is not only about blocking obvious conflict at onboarding. It is about keeping incompatible permissions from coexisting after transfers, temporary assignments, emergency elevation, or delayed offboarding. In mature programmes, the control is tied to identity governance, access certification, and entitlement hygiene, not just role design.
What risk builds when conflicting access is allowed to persist?
When SoD is weak across the lifecycle, the organisation loses the ability to rely on role state as a trustworthy signal. A person can move into a new function while retaining access from the old one, which makes control failures hard to spot and easier to normalise. The same pattern also weakens evidence quality, because recertification may confirm an outdated entitlement set rather than the real business position.
For practitioners, the key issue is not only fraud potential. The larger control failure is that governance no longer keeps pace with business change, so exceptions become permanent and review outcomes stop reflecting actual duty boundaries.
Why lifecycle enforcement is the control point that matters most
SoD is strongest when it is enforced at the moments where identity state changes. Joiner events should avoid granting conflicting access up front, mover events should re-evaluate conflicts when responsibilities shift, and leaver events should remove residual entitlements quickly enough that dormant access does not survive the business relationship. Without that continuity, SoD becomes a paper policy that exists in design but not in operation.
This is where lifecycle tooling, approval routing, and periodic access review must work together. If provisioning adds access, but revocation and recertification are slow or inconsistent, the control degrades over time. In practice, the most dangerous gaps are the ones that appear temporary but never get remediated.
Risk and Threat Considerations
Weak SoD across the identity lifecycle creates a durable abuse path: conflicting access can be used for self-approval, payment manipulation, or unreviewed administrative change. It also increases the chance that stale privileges survive role changes, which expands blast radius when an account is misused or compromised.
Failure mechanism: Access is granted or retained in one stage of the lifecycle without re-checking incompatible duties at the next stage, so conflicting entitlements accumulate and remain active after business responsibility changes.
Impact: Organisations can end up with unauthorized transactions, concealed privilege abuse, weaker auditability, and slower remediation because control evidence no longer matches the real access state.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 sets the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-05 — Overprivileged NHI | Conflicting lifecycle access often leaves excess privilege in place. |
| NHI-01 — Improper Offboarding | Leaver-stage failures let conflicting access survive after separation. | |
| Recommendation — Continuously recertify and remove excess entitlements when roles change. Revoke access promptly at separation and verify residual privileges are gone. | ||
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | SoD depends on lifecycle account provisioning, modification, and removal. |
| AC-5 — Separation of Duties | This control directly addresses incompatible duties and conflicting access. | |
| AC-6 — Least Privilege | Persistent conflicting access usually reflects privilege that outlasts need. | |
| Recommendation — Enforce account lifecycle changes with approved workflows and timely revocation. Define conflicting duties and block combinations that create self-approval risk. Limit each identity to the minimum access needed for its current role. | ||
| ISO/IEC 27001:2022 | A.5.15 — Access control | Lifecycle SoD is implemented through access control policy and enforcement. |
| A.5.18 — Access rights | Conflicting access persists when rights are not reviewed and removed on change. | |
| Recommendation — Apply access rules consistently across joiner, mover, and leaver changes. Review and withdraw access rights when duties change or end. | ||
Practitioner Guidance
What to verify: Confirm that SoD checks run at provisioning, role change, and removal, not only during annual review. If a control only tests the current role catalogue but does not re-evaluate historical entitlements, it will miss the highest-risk conflicts.
What good looks like: The access model should show a clear decision trail for each lifecycle event, with explicit handling of exceptions, temporary elevation, and post-change cleanup. A strong control produces evidence that incompatible access was either prevented or removed promptly, not merely documented after the fact.
Practitioner takeaway: Treat SoD as a lifecycle enforcement problem, not a role-design exercise; the control fails when access is allowed to outlive the business condition that justified it.
Related resources from NHI Mgmt Group
- What breaks when separation of duties checks are not enforced across SAP cloud and on-premises systems?
- When does a machine identity become a compliance problem?
- Why is it important to integrate identity and data governance?
- How should security teams make NHI best practices usable across the business?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org