Join our Newsletter — 33% off our NHI Course
Governance, Ownership & Risk

SoD Controls

← Back to Glossary
By NHI Mgmt Group Updated August 27, 2026 Domain: Governance, Ownership & Risk

SoD controls are segregation of duties checks that prevent a single user or role from holding conflicting permissions across sensitive business activities. In SAP migrations, these controls must be rebuilt or validated against the target process design so that risk is assessed in the new environment, not assumed from the old one.

Expanded Definition

SoD controls, or segregation of duties controls, are designed to stop a single identity from accumulating conflicting permissions that would let one role request, approve, and execute a sensitive action without oversight. In NHI and IAM programs, the concept applies not only to human users but also to service accounts, workflows, and agentic automations that can trigger business-impacting transactions. The control objective is to preserve independent review across the process, even when access is delivered through roles, entitlements, or delegated execution paths.

In SAP migration and redesign projects, SoD is rarely a simple copy-forward of existing rules. Business processes often change, transaction codes are replaced, and legacy exceptions no longer map cleanly to the target system. That is why SoD must be validated against the future-state process model, not inherited as an assumption from the source environment. Guidance varies across vendors on how much automation should be used, but the governance principle is consistent: conflicting capabilities should be detected before go-live, not after.

For broader identity governance context, NHI Mgmt Group’s Ultimate Guide to NHIs — Standards shows how privilege control, lifecycle enforcement, and access review fit together. The most common misapplication is treating SoD as a static audit checklist, which occurs when teams fail to remap conflicts after process changes or system migrations.

Examples and Use Cases

Implementing SoD controls rigorously often introduces workflow friction, requiring organisations to weigh faster execution against stronger oversight and reduced fraud risk.

  • A finance user can create a vendor record but cannot also approve the payment run for that vendor, forcing a separate approver to validate the transaction.
  • During an SAP migration, legacy conflict rules are rebuilt for the target process design so that old role names do not hide new permission combinations.
  • An AI agent that prepares purchase orders is prevented from also approving the same orders, with a human reviewer retained for the final decision path.
  • A privileged service account can deploy code to production, but a different identity must approve the release ticket and confirm the change window.
  • Teams align conflict analysis with identity governance and control testing guidance from the NIST Cybersecurity Framework 2.0 while using NHI-specific inventory data from Ultimate Guide to NHIs — Standards to identify non-human actors.

In practice, SoD findings often surface when access reviews, role engineering, or transaction testing reveal that one identity can both initiate and complete a high-risk business event.

Why It Matters in NHI Security

SoD failures are especially dangerous in NHI environments because service accounts, API keys, and automated agents can operate at machine speed and across many systems. When a single non-human identity holds conflicting privileges, the control gap is not just a policy issue, it becomes an exploit path for fraud, data tampering, and unauthorized release activity. NHIMG research shows that 97% of NHIs carry excessive privileges, which makes conflict detection a critical part of any mature governance program. The same research also notes that 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, reinforcing that SoD is a foundational trust-control, not a niche compliance exercise.

Practitioners should connect SoD analysis to access visibility, role mining, and secret governance so that a hidden automation account does not silently inherit conflicting duties. This matters most where privileged workflows are embedded in CI/CD, ERP, or support automation, because the business impact scales quickly once an identity can both authorize and perform sensitive actions. The operating assumption should be that every privileged automation path can become a control bypass unless it is explicitly constrained. Organisations typically encounter the operational impact only after a fraudulent change, payment anomaly, or audit finding exposes that one identity could both act and attest, at which point SoD controls become operationally unavoidable to address.

Related governance evidence is documented in Ultimate Guide to NHIs — Standards, which also frames broader lifecycle and privilege concerns alongside identity governance baselines.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 and OWASP Agentic AI Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-04SoD reduces conflicting permissions across non-human identities and automations.
NIST CSF 2.0PR.AAAccess control and entitlement governance underpin segregation of duties enforcement.
NIST Zero Trust (SP 800-207)Zero Trust requires continuous verification and constrained privilege for each action path.
NIST SP 800-63Digital identity assurance supports preventing one identity from self-approving sensitive actions.
OWASP Agentic AI Top 10Agentic systems must not retain end-to-end authority over conflicting business steps.

Map conflicting duties, then enforce least privilege and independent review across sensitive workflows.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org