Segregation of Duties (SoD)
Ensuring no single user can complete a sensitive process unilaterally, for example, both creating and approving a vendor payment. SoD policies are encoded into IGA tools and tested during access certification.
Segregation of duties is where governance gets specific enough to be useful: the policy names two entitlements that must not coexist on one person, and the system enforces it at request time rather than discovering the violation at audit. The hard part is authoring the ruleset, since it requires business process knowledge that lives with finance and operations rather than with IT.
See also: access certification, what is IGA, entitlement, IGA vendors
Related on Start with Identity
- GlossaryCIEM
Cloud Infrastructure Entitlement Management. Tools that discover and right-size identities and permissions across AWS, Azure, and GCP, reducing excessive and un
- GlossaryIAM
Identity and Access Management. Workforce identity for employees, contractors, and partners. Covers authentication, authorization, lifecycle, and audit. Distinc
- GlossaryIGA
Identity Governance and Administration. The discipline of managing who has access to what, why, and for how long. Covers access certification, segregation of du
- BlogServiceNow closes its Veza acquisition at about 1.2 billion dollars
Announced in December 2025 and closed on 2 March 2026, substantially in cash. Veza, valued at 808 million dollars in its Series D, now supplies the permission g