$ every product image on this site is an unretouched screenshot of the running platform — demo tenant, fictional people, captured live
⚔️ Platform · SoD

Toxic combinations,
declared once.

"Vendor maintenance in Workday" plus "payment approval in SAP" should never meet in one person. Declare it once — the evaluator flags every identity holding both sides, across systems, however they got there.

Cross-system by design

One engine, everywhere the risk lives.

SoD rules are condition pairs over your entitlement estate — cross-system, continuously evaluated. A dry-run previews violations before a rule goes live, and severity drives both how the finding is routed and the holder's risk score.

  • Both sides of every violation named, per person
  • Dry-run preview before a rule is saved — nothing is stored until you save
  • Conditions, not hand-listed entitlement pairs — a new entitlement that matches the condition is in scope the day it appears
app.rapidvalue.eu/sod-workbench · conflicts
SoD conflicts — every violation with both sides named, per person, across systems
conflicts — both sides named, per person, across systems

A business decision, kept human

Which side to revoke is your call — deliberately.

Auto-revoking one side of a toxic combination would break legitimate work. Violations surface as findings in the Advisor, routed to the security and risk team — not into a reviewer's day-to-day inbox — and weigh into the holder's risk score. The resolution is a considered decision, with the evidence attached.

  • Violations weighted by rule severity in the identity risk score
  • SoD posture visible in the compliance control center
  • Deliberately no auto-revoke of access someone already has — taking it away is a human decision
  • A violation whose question disappeared — the grant was revoked elsewhere — closes itself as superseded rather than waiting for a reviewer to notice
  • Prevention is the other half: a rule set to block stops the conflicting side being provisioned in the first place — either with a time-boxed overrule as the escape hatch, or with no exception at all
…/advisor
a SoD violation opened in the Advisor — both sides named, routed to the security and risk team
a violation opened in the Advisor — routed, explained, and tunable

Governed vocabulary, seeded per framework

Compliance packs and compensating controls, built in.

SoD rules cite a managed vocabulary — categories, framework references and compensating controls — seeded from activatable packs for SOX, GDPR, ISO/IEC 27001 and HIPAA. An overrule is time-boxed by a tenant-wide cap and carries its compensating control, so an exception is a documented decision instead of a shrug.

  • Framework packs seed categories, citations and controls — idempotent, your edits survive
  • Compensating controls are picked from the managed list, reused everywhere
  • A tenant-wide overrule cap bounds every exception, and a per-rule policy can set its own cap and approval chain
…/sod-workbench · settings
SoD settings — compliance packs, managed vocabularies, compensating controls, the overrule cap
compliance packs · managed vocabularies · compensating controls · the overrule cap

See SoD evaluated on your own data.

A 30-minute kickoff connects your HR feed and one system — working POC the same day.

Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.