Security & governance · Glossary term

What is Separation of Duties?

Dividing conflicting responsibilities or authority across independent roles so one principal cannot complete a high-risk action without another authorized decision.

Why does Separation of Duties matter?

A compromised account or mistaken agent should not be able to propose, approve, execute, and conceal the same consequential change.

Separation of Duties in practice

Separate artifact creation from release approval, use distinct identities, preserve both decisions in the audit log, and define emergency access with later review.

What is the common confusion about Separation of Duties?

Separation of duties is about conflicting authority, not simply assigning work to several people or agents that share the same credentials.

Learn Separation of Duties in the course

No lesson links to this term yet. Search the course catalog for it.

  • Approval GateA control point that blocks a consequential action until an authorized person or policy grants permission.
  • Reviewer AgentAn agent assigned to inspect another agent's artifact or decision against explicit criteria and return findings or a verdict.
  • Audit LogA durable, access-controlled record of security- or accountability-relevant events, including who or what acted, what changed, when it…
  • Least PrivilegeGiving a model, agent, tool, or user only the permissions required for the current task, for only as long as those permissions are needed.

Sources

More terms in Security & governance

Open the Security & governance list in the glossary

This entry comes from glossary/terms.md on GitHub. Browse all 250 glossary terms.