Compliance

SoD Remediation

When a SoD violation is detected -- either through SimulateGrant blocking a new grant or through a periodic scan of existing entitlements -- a remediation record is created. Each record tracks the conflicting roles, the affected user, the detection method, the remediation action taken (revoke, reassign, or exception grant), and who approved the resolution.

The remediation log provides auditors with a complete history of SoD violation handling, including before/after permission states. Exportable in PDF and CSV for SOC 2 and ISO 27001 evidence packages.

SoD Remediation screenshot

Key Configuration

  • Auto-remediation rules (revoke lower-privilege role)
  • Exception grant approval chain
  • Exception expiration duration
  • Export format (PDF / CSV)
All documentation Question about this? Talk to us