Create a Separation of Duties rule
Use this guide to create and enforce Separation of Duties (SOD) rules in the Okta Identity Governance to prevent conflicting entitlements and block potential fraud and conflicts of interest.
Okta Identity Governance (OIG) includes Separation of Duties (SOD), which enables administrators to create rules that block the assignment of conflicting entitlements to a user. Using SOD, organizations can divide critical business processes, tasks, or responsibilities to different individuals or roles to prevent fraud and conflicts of interest by a single person. For example, rules can ensure a person doesn't have the privilege to both create and approve a purchase order. This feature uses Entitlement Management to ensure users have the correct permissions for each resource.
This resource is designed for Super Admins who have access to OIG, the Entitlement Management app, and the Access Request and Access Certification apps, who are responsible for configuring SOD rules within the Okta Admin console.