Incompatible authority
Separation of duties prevents one actor from holding or exercising combinations of authority that can conceal error or abuse. Common splits include request and approval, development and production release, payment creation and release, and policy authoring and deployment.
Static and dynamic controls
Static separation prevents incompatible roles or grants from being assigned to the same principal. Dynamic separation permits both capabilities but prevents the same actor from using them in one transaction, case, or time window. High-impact actions can require two independent approvals.
Preserve independence
Use distinct principals, authenticators, approval records, and decision paths. Verify that group nesting, service accounts, delegation, emergency access, and administrators cannot recombine the separated powers. Make the second actor see the exact resource, action, and change before approval.
Failure and residual risk
Two role names can still resolve to one human or shared credential. An approver can rubber-stamp a vague request. A privileged administrator can bypass the workflow. Colluding actors can defeat the control. Too much separation can delay recovery and create unsafe informal workarounds.
Pomerium boundary
Pomerium can require identity and context for separate routes or administrative tools. The application or workflow system must enforce transaction-level separation, approval order, actor independence, and action binding. Route access alone cannot prove that two distinct actors approved one business action.
Evaluation checklist
- Which authority combinations would let one actor conceal error or abuse?
- Are conflicts checked across direct grants, nested groups, delegation, and service accounts?
- Does approval show and bind the exact resource, action, and version?
- Can an administrator or emergency path recombine the separated duties?
- Do evidence and tests prove that independent actors completed the required steps?
