Risk Management Use Case: Manage Toxic Combinations (requires IGA)
Risk Management Use Case: Manage Toxic Combinations (requires IGA)
Use Case Description
This use case describes how IGA Admin or Security Manager can manage toxic combinations, also known as Separation of Duties (SoD) or Segregation of Duties. Toxic combinations can either be forbidden or denied, and depending on the type, the user and/or manager are informed.
Example Scenario
An IGA Admin identifies that having access to both financial approval and payroll processing creates a toxic combination that could lead to fraud. They set up this combination as denied in the IGA solution. When a user requests access that would result in this combination, the request is automatically prevented, and notifications are sent to the relevant managers and the user, ensuring the combination is not allowed.
Use Case Diagram

Workflow
Please find more information from the use case description: IGA Use Case - Manage Toxic Combinations.
Results
- Toxic combinations are prevented or forbidden from the user.
- Email notifications are sent to the relevant parties.
Benefits
- Enhances security by preventing potential conflicts of interest.
- Ensures compliance with internal and external audit requirements.
- Provides clear visibility and accountability for access rights management.
Table of Contents