A monitoring approach that reviews existing entitlements against separation-of-duties rules after access has been granted. It is used to find hidden conflicts, inherited risk, and access drift that preventive request-time controls may not catch.
What Detective SoD Analysis Does
Detective separation-of-duties analysis is a post-access monitoring control. It reviews who already has access, then checks those entitlements against SoD rules to surface conflicts that were missed at request time or created later through drift.
That makes it different from preventive approval workflows. A well-designed detective review can reveal inherited access, accumulated exceptions, and privilege combinations that become risky only when they exist together.
Where It Fits in Access Governance
In practice, detective SoD analysis sits inside access governance and entitlement review. It is most useful where access is dynamic, roles change frequently, or control decisions are distributed across business systems that do not share one consistent approval path.
The control is also important because SoD rules are only useful if they continue to reflect real access. If the rule set is stale, the analysis may miss true conflicts or raise noise on access that is technically valid but operationally obsolete.
For a practical SoD reference point, see Segregation of Duties (SoD) Guide.
What Detective SoD Analysis Finds
This analysis typically looks for toxic combinations such as request-and-approve, create-and-pay, or administer-and-audit patterns, but it is broader than fraud scenarios alone. It can also uncover inherited access from role design, emergency access that was never removed, and composite access spread across multiple systems.
The output is usually a conflict set that needs triage, not an automatic denial. Some conflicts are real issues, while others are mitigated by compensating controls, business process design, or narrowly scoped exceptions that should still be reviewed and documented.
How to Interpret the Results
The value of detective SoD analysis is in separating harmless overlap from material exposure. A conflict becomes meaningful when the same person or non-human principal can complete a sensitive business process without independent review, or when access drift creates a pathway around intended control boundaries.
Results should therefore be read as control evidence, not just as exceptions. They show where the access model, role model, or exception governance is no longer aligned with actual usage and business reality.
Detective SoD analysis is strongest when paired with broader control validation such as NIST SP 800-53 Rev 5 Security and Privacy Controls and NIST Cybersecurity Framework 2.0, because both reinforce ongoing monitoring and governance of access risk.
Risk and Threat Considerations
Detective SoD analysis addresses a real exposure gap: preventive controls often approve access once, but they do not always catch later role changes, inherited entitlements, or cross-system combinations that become dangerous over time. That creates a control blind spot where accumulated access can support fraud, misuse, or unauthorized sensitive actions.
Failure mechanism: Access drift, exception creep, or incomplete role modeling allows a user or principal to hold conflicting permissions simultaneously, so the conflict exists even though no single request looked unsafe.
Impact: The organisation can end up with hidden privilege paths, weak auditability, and business-process conflicts that increase the likelihood of fraud, policy breach, or unreviewed high-risk actions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, NIST CSF 2.0 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Detective SoD analysis depends on reviewing entitlement evidence after access changes. |
| AC-5 — Separation of Duties | The term is directly about enforcing separation of duties as an access-control principle. | |
| Recommendation — Review entitlement and conflict findings regularly to identify access drift and unresolved SoD exceptions. Map SoD rules to AC-5 and verify that conflicting duties are prevented or detected across critical workflows. | ||
| NIST CSF 2.0 | DE.CM-01 — Networks and network services are monitored to detect potential cybersecurity events | The term is a monitoring approach that detects access-condition anomalies after provisioning. |
| Recommendation — Monitor entitlement changes and access conflicts so detective reviews surface drift early. | ||
| ISO/IEC 27001:2022 | A.5.18 — Access rights | SoD analysis is part of governing and reviewing access rights over time. |
| Recommendation — Review access rights periodically and resolve conflicting entitlement combinations. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Detective SoD analysis is an access governance control used to identify excessive or conflicting access. |
| Recommendation — Use access control management reviews to find toxic permission combinations and entitlement drift. | ||
Practitioner Guidance
What to watch for: Focus review effort on high-value processes, legacy roles, emergency access, and systems with frequent entitlement change. Those are the places where detective SoD analysis is most likely to reveal meaningful drift rather than harmless duplication.
Governance implication: Treat conflicts as governance findings that need ownership, not just alerts to close. The practical question is whether the conflict is mitigated, remediated, or intentionally accepted with evidence, because unresolved exceptions tend to accumulate into systemic access risk.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 8, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org