Compliance
SoD Remediation
When a SoD violation is detected -- either through SimulateGrant blocking a new grant or through a periodic scan of existing entitlements -- a remediation record is created. Each record tracks the conflicting roles, the affected user, the detection method, the remediation action taken (revoke, reassign, or exception grant), and who approved the resolution.
The remediation log provides auditors with a complete history of SoD violation handling, including before/after permission states. Exportable in PDF and CSV for SOC 2 and ISO 27001 evidence packages.
Key Configuration
- Auto-remediation rules (revoke lower-privilege role)
- Exception grant approval chain
- Exception expiration duration
- Export format (PDF / CSV)