Skip to main content
Joinly by KoppelHet

Product · Governance & security

Prevent dangerous combinations of permissions before they occur

The greatest access risks are not the hackers at the gate, but the combinations of permissions that silently arise within your own organisation. Joinly automatically monitors segregation of duties and blocks such combinations. Without anyone having to watch over it and without work grinding to a halt.

Segregation of Duties

Suppose a single employee can both create and approve invoices. On paper, these are two separate tasks; together, they represent a wide-open door to undetected fraud. Or someone places orders and also confirms their receipt. And there is no longer anyone to provide a second pair of eyes.

Such "toxic" combinations are rarely the result of a conscious decision. They accumulate over time: someone changes teams but retains their old access, a role gets expanded, an import places someone in a group. Each step is justifiable. The sum of it all is the risk.

And that risk is real. It opens the door to fraud and errors that are only noticed after the fact. It is a recurring finding in audits under ISO 27001, NEN 7510 and SOX-like frameworks. And it is deceptive, because no one oversees the entire sum at the right moment. That is why "paying closer attention" is not a solution; this is something a system should monitor.

What is Segregation of Duties?

Functiescheiding is het principe dat bepaalde taken niet in één paar handen mogen liggen, omdat de combinatie fraude of fouten mogelijk maakt. Wie een betaling kan invoeren, hoort hem niet ook zelf te kunnen goedkeuren. Het is een van de oudste en meest universele controles in interne beheersing en een vaste eis in vrijwel elk compliance-kader.

A simple principle, but difficult to execute. In most organisations, segregation of duties exists only in an Excel authorisation matrix that nobody maintains, or in a monthly retrospective check. This means a prohibited combination can exist for weeks before anyone notices it—if it is noticed at all. Manual monitoring does not scale with the pace at which access changes in a modern organisation.

  1. Fraud & errors

    Anyone who can both enter and approve data can control themselves. This is precisely where opportunities for fraud and undetected errors arise.

  2. Audit findings

    Segregation of duties is a standard control in ISO 27001, NEN 7510, and SOX-like frameworks. If you cannot demonstrate that you monitor it, it is invariably an audit finding.

  3. Invisible until it goes wrong

    Toxic combinations accumulate over time—a role change here, an import there. No one sees the whole picture at the right moment.

Segregation of duties in Joinly

Those who create invoices must not also approve them. Joinly automatically monitors such combinations and prevents them before they occur.

Het instellen van een conflict in Joinly: op het tabblad Conflicts bepaal je welke toegangsitems niet samen mogen, zodat Joinly de combinatie tegenhoudt.

Separation of duties made easy

With Joinly Segregation of Duties, separation of duties becomes easy. No complex projects and expensive consultants, but simple workflows you set up yourself.

  • Openstaande functiescheidingsconflicten in Joinly: nieuwe botsingen wachten op een keuze, bestaande toegang blijft staan.

    Always in control

    Existing access remains unchanged; only new conflicts will await a decision. If a conflict resolves itself, access is granted automatically.

  • De auditlog van een functiescheidingsconflict in Joinly: wie welke keuze maakte, wanneer en waarom.

    Audit-ready

    Every choice and every change is logged. Who, what, and why. This is how you answer the auditor's question with evidence that is already there.

  • Een workflow in Joinly die bij een functiescheidingsconflict de leidinggevende inseint en een goedkeuring start.

    Workflows

    A conflict can automatically alert the manager or initiate an approval. This immediately turns a notification into a process.

Ask away

Frequently asked questions

<p>If you're having trouble with the frequently asked questions, feel free to send us a message.</p>

Frequently asked questions about workflows

Does someone lose access they need?

No. Permitted changes will proceed. Only a new conflicting request will wait for a decision.

What are the practical implications of SoD?

Very little — and that is the intention. The dangerous combination no longer occurs, without anyone having to pay attention.

Does SoD help with an audit?

Yes. You can always show who made which choice and why.

See what Joinly can do for your organisation?

Start a free trial today or get in touch for advice on your HR and Microsoft environment.