Enhancing Access Management and Segregation of Duties (SoD)
A leading sustainable urban development focused on clean energy, innovation, and smart city technologies.
The business situation
Client faced key challenges in managing access controls and enforcing Segregation of Duties (SoD) across its critical enterprise applications, Oracle ERP, Salesforce, Yardi, and Ivalua. The gaps posed potential compliance and operational risks. Key issues identified:
User roles and permissions were not uniformly governed across systems, leading to potential unauthorized access and conflicting privileges across departments.
The lack of automated SoD monitoring resulted in undetected conflicts, exposing the organization to risks of fraud and control failures.
User provisioning and de-provisioning processes were manual, time-consuming, and error-prone, with limited audit trails and inadequate documentation.
The absence of a unified SoD framework across applications increased the risk of non-compliance with internal policies and external regulations.
Our team’s role
Access Assessment
Conducting focused discussions with business and IT stakeholders to understand current access challenges, role overlaps, and compliance risks across functions
SoD Matrix Development
Developing a tailored SoD matrix by analyzing critical business processes and identifying incompatible role combinations
User Role Mapping
Mapping existing users to appropriate job roles and system access levels in line with the SoD matrix and organizational governance policies
Gap Identification
Identifying access control gaps, role design flaws, and excessive privileges
Recommendations
Recommending updates to roles, permissions, and provisioning processes to enhance compliance and reduce risk
The value our team added
Resolved critical SoD conflicts across Oracle, Salesforce, Ivalua, and Yardi, reducing compliance and fraud risks.
Standardized roles and access by designing a robust SoD matrix and aligning user roles with policies.
Improved audit readiness through precise documentation and visibility into access controls across systems.
Enabled future automation by laying a strong foundation for streamlined access governance and control monitoring.
Strengthen Access Governance
From SoD Design to Risk-Based Role Rationalization and Compliance Uplift