---
title: Separation of Duties (SOD) in RBAC
description: Once you are controlling permissions and access with roles (using Role based access control aka RBAC), it is simple to make roles mutually exclusive.
image: https://blog.empowerid.com/hs-fs/file-18502615-jpg/images/separation_of_duties_rbac.jpg
---

[![empowerID-logo](https://blog.empowerid.com/hubfs/empowerID-logo.svg "empowerID-logo")](http://www.empowerid.com)

**![phone](https://blog.empowerid.com/hubfs/images/phone.svg)   1-877-996-4276   **or**  +1 (614) 652-6825**

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](https://www.facebook.com/220903377569) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](https://www.linkedin.com/company/85780) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/EmpowerID) [![Share on pinterest](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/pinterest-color.png?width=24&name=pinterest-color.png) ](http://www.youtube.com/user/empowerID)

# All-In-One Identity Management and Cloud Security

Emerging technologies are challenging old paradigms and unveiling new ways of approaching the security discipline that enables the right individuals to access the right resources at the right times for the right reasons.

EmpowerID has embedded innovative technologies in every aspect, providing flexible and mature IAM capabilities in the cloud, on premise and in hybrid environments, addressing the mission-critical need across increasingly heterogeneous technology environments, and meeting increasingly rigorous compliance requirements.

# Separation of Duties (SOD) in RBAC

Posted by [Edward Killeen](https://blog.empowerid.com/blog-1/author/edward-killeen) on Tue, Jul 17, 2012

- [Tweet](https://twitter.com/share)

You know that guy in accounting you just don't like and wish you didn't have to talk to?  Well, there's a chance that you don't have to!  Separation of Duties (SOD) to the rescue.

![separation of duties RBAC](https://blog.empowerid.com/hs-fs/file-18502615-jpg/images/separation_of_duties_rbac.jpg)It doesn't really work like that but there are some mutually exclusive roles.  One where if you have these sets of permissions, you cannot have another set of permissions.  Some of these are security related (for example, you have permission to create a user, you should not have permission to add them to the financials group, this keeps one person from being able to create a fake user to access critical financial reports).  Some are regulatory (for example, in a bank the analysts should not be able to have access to customer records, the bankers should not have access to analyst reports).

Once you are controlling permissions and access with roles (using Role based access control aka RBAC), it is simple to make roles mutually exclusive.  If you are a member of one role, you cannot be a member of another.  If you are a member of one role, you need CEO approval to be a member of another.  This creates a separation of duties.

I always picture it in action like a Hollywood movie...you need two keys to detonate the bomb and there is a tense standoff as the one guy knows they shouldn't do it.  Separation of duties is just like that.  [Just. Like. That.](http://en.wikipedia.org/wiki/Two-man_rule)

Once you've configured your roles to show what your users can do, you need to take that next deeper dive into what that same user shouldn't be able to do.  A good mapping of roles and SOD rules will make your organization more secure and your auditors much happier. 

If you are one of those "a picture is worth a thousand words" types, give us 15 minutes to show you how SOD works in RBAC by [scheduling a demonstration](https://blog.empowerid.com/scheduledemo/).

[![Click me](https://no-cache.hubspot.com/cta/default/174819/0974a7ec-13db-478e-89be-961a3ef709a9.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/0974a7ec-13db-478e-89be-961a3ef709a9)

 Tags: [Role Based Access Control (RBAC)](https://blog.empowerid.com/blog-1/topic/role-based-access-control-rbac)

### About EmpowerID

EmpowerID is the all-in-one Identity Management and Cloud Security platform designed for people.  Globally managing millions of identities in diverse enterprises, EmpowerID offers comprehensive provisioning, single sign-on and access governance coupled with an industry leading user experience. 

Built on a single codebase for manageability and scalability, EmpowerID ships with a powerful API, a visual workflow designer and over 400 ready-to-use workflows for rapid deployment.

 

[![Free Evaluation of EmpowerID](https://no-cache.hubspot.com/cta/default/174819/daebe087-5275-487d-bf53-bb1d39fb9dc4.png)](https://cta-redirect.hubspot.com/cta/redirect/174819/daebe087-5275-487d-bf53-bb1d39fb9dc4)

### Latest Posts

### Posts by category

- [2-Factor (2)](https://blog.empowerid.com/blog-1/topic/2-factor)
- [Access Governance (36)](https://blog.empowerid.com/blog-1/topic/access-governance)
- [Active Directory (46)](https://blog.empowerid.com/blog-1/topic/active-directory)
- [Attestation (4)](https://blog.empowerid.com/blog-1/topic/attestation)
- [authentication (6)](https://blog.empowerid.com/blog-1/topic/authentication)
- [authorization (2)](https://blog.empowerid.com/blog-1/topic/authorization)
- [azure (1)](https://blog.empowerid.com/blog-1/topic/azure)
- [Azure security (2)](https://blog.empowerid.com/blog-1/topic/azure-security)
- [azuread (1)](https://blog.empowerid.com/blog-1/topic/azuread)
- [Cisco (1)](https://blog.empowerid.com/blog-1/topic/cisco)
- [Citrix (1)](https://blog.empowerid.com/blog-1/topic/citrix)
- [cloud (1)](https://blog.empowerid.com/blog-1/topic/cloud)
- [cloud security (28)](https://blog.empowerid.com/blog-1/topic/cloud-security)
- [consumers (2)](https://blog.empowerid.com/blog-1/topic/consumers)
- [Data Governance (5)](https://blog.empowerid.com/blog-1/topic/data-governance)
- [dataprivacy (1)](https://blog.empowerid.com/blog-1/topic/dataprivacy)
- [DirSync (1)](https://blog.empowerid.com/blog-1/topic/dirsync)
- [eic (1)](https://blog.empowerid.com/blog-1/topic/eic)
- [Federation (6)](https://blog.empowerid.com/blog-1/topic/federation)
- [Gartner (1)](https://blog.empowerid.com/blog-1/topic/gartner)
- [GDPR (2)](https://blog.empowerid.com/blog-1/topic/gdpr)
- [Governance and Regulatory Compliance (4)](https://blog.empowerid.com/blog-1/topic/governance-and-regulatory-compliance)
- [GRC (3)](https://blog.empowerid.com/blog-1/topic/grc)
- [Group Management (12)](https://blog.empowerid.com/blog-1/topic/group-management)
- [IAG (4)](https://blog.empowerid.com/blog-1/topic/iag)
- [IAM (34)](https://blog.empowerid.com/blog-1/topic/iam)
- [IDaaS (1)](https://blog.empowerid.com/blog-1/topic/idaas)
- [Identity and Access Management (IAM) (68)](https://blog.empowerid.com/blog-1/topic/identity-and-access-management-iam)
- [Identity Management (6)](https://blog.empowerid.com/blog-1/topic/identity-management)
- [iga (1)](https://blog.empowerid.com/blog-1/topic/iga)
- [M365 security (1)](https://blog.empowerid.com/blog-1/topic/m365-security)
- [Magic Quadrant (1)](https://blog.empowerid.com/blog-1/topic/magic-quadrant)
- [O365 (1)](https://blog.empowerid.com/blog-1/topic/o365)
- [Office 365 (3)](https://blog.empowerid.com/blog-1/topic/office-365)
- [open policy agent (1)](https://blog.empowerid.com/blog-1/topic/open-policy-agent)
- [Palo Alto (1)](https://blog.empowerid.com/blog-1/topic/palo-alto)
- [Password management (13)](https://blog.empowerid.com/blog-1/topic/password-management)
- [Privacy and EU-US Data Transfers (1)](https://blog.empowerid.com/blog-1/topic/privacy-and-eu-us-data-transfers)
- [Privacy Shield (1)](https://blog.empowerid.com/blog-1/topic/privacy-shield)
- [Radius (1)](https://blog.empowerid.com/blog-1/topic/radius)
- [RBAC (2)](https://blog.empowerid.com/blog-1/topic/rbac)
- [Role Based Access Control (RBAC) (40)](https://blog.empowerid.com/blog-1/topic/role-based-access-control-rbac)
- [SAML (4)](https://blog.empowerid.com/blog-1/topic/saml)
- [Separation of Duties (2)](https://blog.empowerid.com/blog-1/topic/separation-of-duties)
- [SharePoint (8)](https://blog.empowerid.com/blog-1/topic/sharepoint)
- [siemens (1)](https://blog.empowerid.com/blog-1/topic/siemens)
- [Single Sign-on (1)](https://blog.empowerid.com/blog-1/topic/single-sign-on)
- [Single Sign-on (SSO) (26)](https://blog.empowerid.com/blog-1/topic/single-sign-on-sso)
- [social media (1)](https://blog.empowerid.com/blog-1/topic/social-media)
- [SSO (3)](https://blog.empowerid.com/blog-1/topic/sso)
- [User provisioning (28)](https://blog.empowerid.com/blog-1/topic/user-provisioning)
- [VDS (1)](https://blog.empowerid.com/blog-1/topic/vds)
- [Virtual Directory (28)](https://blog.empowerid.com/blog-1/topic/virtual-directory)
- [WS-Fed (2)](https://blog.empowerid.com/blog-1/topic/ws-fed)

### Subscribe via E-mail

Share This Page

[![Share on facebook](https://7528309.fs1.hubspotusercontent-na1.net/hub/7528309/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/facebook-color.png?width=24&name=facebook-color.png) ](http://www.facebook.com/share.php?u=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F190801%2FSeparation-of-Duties-SOD-in-RBAC%3Futm_medium%3Dsocial%26utm_source%3Dfacebook) [![Share on linkedin](https://7528302.fs1.hubspotusercontent-na1.net/hub/7528302/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/linkedin-color.png?width=24&name=linkedin-color.png) ](http://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F190801%2FSeparation-of-Duties-SOD-in-RBAC%3Futm_medium%3Dsocial%26utm_source%3Dlinkedin) [![Share on twitter](https://7528304.fs1.hubspotusercontent-na1.net/hub/7528304/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/twitter-color.png?width=24&name=twitter-color.png) ](https://twitter.com/intent/tweet?original_referer=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F190801%2FSeparation-of-Duties-SOD-in-RBAC%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&url=https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F190801%2FSeparation-of-Duties-SOD-in-RBAC%3Futm_medium%3Dsocial%26utm_source%3Dtwitter&source=tweetbutton&text=) [![Share on email](https://7528311.fs1.hubspotusercontent-na1.net/hub/7528311/hubfs/raw_assets/public/mV0_d-web-default-modules_hubspot/img/email-color.png?width=24&name=email-color.png) ](mailto:?subject=Check%20out%20https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F190801%2FSeparation-of-Duties-SOD-in-RBAC%3Futm_medium%3Dsocial%26utm_source%3Demail%20&body=Check%20out%20https%3A%2F%2Fblog.empowerid.com%2Fblog-1%2Fbid%2F190801%2FSeparation-of-Duties-SOD-in-RBAC%3Futm_medium%3Dsocial%26utm_source%3Demail)

![](https://blog.empowerid.com/hubfs/images/logo-empowerid.svg)

4393 Tuller Road  
Dublin OH

EmpowerID is a registered trademark and  
trade name of The Dot Net Factory, LLC.  
EmpowerID

© 2021 EmpowerID

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Edward Killeen",
    "url" : "https://blog.empowerid.com/blog-1/author/edward-killeen"
  },
  "datePublished" : "2012-07-17T14:03:00.000Z",
  "headline" : "Separation of Duties (SOD) in RBAC",
  "image" : [ "https://blog.empowerid.com/hs-fs/file-18502615-jpg/images/separation_of_duties_rbac.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.empowerid.com/blog-1/bid/190801/Separation-of-Duties-SOD-in-RBAC",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.empowerid.com/hubfs/Asset%201.svg"
    },
    "name" : "EmpowerID"
  }
}
```