Product · Governance & security

Prevent dangerous combinations of permissions before they occur

Prevent dangerous combinations of permissions before they occur

The greatest access risks are not the hackers at the gate, but the combinations of permissions that silently arise within your own organisation. Joinly automatically monitors segregation of duties and blocks such combinations. Without anyone having to watch over it and without work grinding to a halt.

  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo
  • Brand Logo

Segregation of Duties

Suppose a single employee can both create and approve invoices. On paper, these are two separate tasks; together, they represent a wide-open door to undetected fraud. Or someone places orders and also confirms their receipt. And there is no longer anyone to provide a second pair of eyes.

Such "toxic" combinations are rarely the result of a conscious decision. They accumulate over time: someone changes teams but retains their old access, a role gets expanded, an import places someone in a group. Each step is justifiable. The sum of it all is the risk.

And that risk is real. It opens the door to fraud and errors that are only noticed after the fact. It is a recurring finding in audits under ISO 27001, NEN 7510 and SOX-like frameworks. And it is deceptive, because no one oversees the entire sum at the right moment. That is why "paying closer attention" is not a solution; this is something a system should monitor.

What is Segregation of Duties?

Segregation of duties is the principle that certain tasks must not be performed by the same person, as the combination can facilitate fraud or errors. Someone who can enter a payment should not also be able to approve it themselves. It is one of the oldest and most universal controls in internal management and a standard requirement in almost every compliance framework.

A simple principle, but difficult to execute. In most organisations, segregation of duties exists only in an Excel authorisation matrix that nobody maintains, or in a monthly retrospective check. This means a prohibited combination can exist for weeks before anyone notices it—if it is noticed at all. Manual monitoring does not scale with the pace at which access changes in a modern organisation.

01

Fraud & errors

Anyone who can both enter and approve data can control themselves. This is precisely where opportunities for fraud and undetected errors arise.

02

Audit findings

Segregation of duties is a standard control in ISO 27001, NEN 7510, and SOX-like frameworks. If you cannot demonstrate that you monitor it, it is invariably an audit finding.

03

Invisible until it goes wrong

Toxic combinations accumulate over time—a role change here, an import there. No one sees the whole picture at the right moment.

Segregation of duties in Joinly

Those who create invoices must not also approve them. Joinly automatically monitors such combinations and prevents them before they occur.

Set up rule

Ask away

Frequently asked questions

Got Questions?
We've Got Answers

Frequently asked questions

<p>If you're having trouble with the frequently asked questions, feel free to send us a message.</p>

<p>If you're having trouble with the frequently asked questions, feel free to send us a message.</p>

Frequently asked questions about workflows
No. Permitted changes will proceed. Only a new conflicting request will wait for a decision.

See what Joinly can do for your organisation?

Start a free trial today or get in touch for advice on your HR and Microsoft environment.

See what Joinly can do for your organisation?

Start a free trial today or get in touch for advice on your HR and Microsoft environment.

See what Joinly can do for your organisation?

Start a free trial today or get in touch for advice on your HR and Microsoft environment.