> For the complete documentation index, see [llms.txt](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.veza.com/4yItIzMvkpAvMVFAamTf/features/separation-of-duties/manage-sod-risks-with-veza.md).

# Managing SoD Risks with Veza

Workflows and recommendations for working with SoD rulesets in Veza.

### Overview

Veza provides queries for detecting SoD violations with a flexible interface for defining combinations of conflicting entitlements that map to your organization's SoD rules. These queries support:

* A **Separation of Duties** overview page for reviewing all SoD queries, with filtering options including query name, risk level, SoD manager, platform (integration type), and labels.
* Using Veza's **Graph** and **Query Builder** search interfaces to investigate risky users, with visibility into the organization, department, last login, access to other apps, and historical access patterns.
* Easy-to-build and customizable **Dashboards** for tracking SoD violations and resolutions, monitoring progress, and reporting to stakeholders.
* Continuous **Rules and Alerts**, with integrated service ticket creation for ServiceNow, Jira, or any target system using Veza Actions and webhooks.
* Integrated **Access Reviews** for streamlined remediation using instant 1-Step reviews or recurring on-demand reviews triggered from SoD query results.

To use Veza to manage SoD risks, we recommend reviewing the out-of-the-box queries available for the integrations you have added to Veza, then using our SoD tool to add more policies into Veza depending on your needs.

### Detection

#### Detecting SoD Violations and Cross-Platform SoD Conflicts

You can model your SoD rulesets in Veza by creating detection queries to search the Veza graph for users with conflicting roles, or permissions.

To add a query, open the **Separation of Duties** overview and click **New SoD Query**. Use the *Separation of Duties* query builder to model each rule by:

* Specifying the type of user the rule applies to (either an identity provider identity or local user account).
* Creating AND/OR statements that define the conflicting permissions or roles across one or more target applications.

You can preview the results before saving the query. When saving the query, you should assign a risk level, add a brief description, risk explanation and document mitigating controls.

See [Creating SoD Detection Queries](/4yItIzMvkpAvMVFAamTf/features/separation-of-duties/sod-queries.md) for more information about the SoD query builder and syntax.

#### Setting Risk Levels for Separation of Duties (SoD) Queries

Each SoD query can be assigned a risk level for organizing your SoD queries by criticality. When a [risk level](/4yItIzMvkpAvMVFAamTf/features/insights/risks.md) is assigned to a query, users in the results are assigned a risk score based on the total number and risk levels of rules they violate.

You can assign risk levels when saving a query, by editing the saved query, or using quick actions on the Separation of Duties landing page.

To change the risk level associated with a saved SoD query and add or update details:

1. Find a query on the Separation of Duties overview and click to view details.
2. In the details view, click **Edit** to open the Save Query dialog.
3. On the Save Query > Details tab, click the **Risk Level** dropdown to set the risk level. Setting this criticality level to low, medium, high, or critical will mark the results of the query as risks and enable risk score generation.
4. Use the **Risk Explanation** field to describe the SoD risk.
5. Use the **Risk Remediation** field to document mitigating controls for the risk.
6. Click **Save Query** at the top right after making your changes.

You also quickly change a risk level directly from the **Separation of Duties** overview by locating the query, opening the **Actions** menu, and choosing **Set Risk Level**.

#### Using Labels to Organize SoD Queries

Queries created with Veza can have labels to organize them based on application, user type, or any other criteria.

You can add labels by editing a saved SoD query:

1. Find a query on the Separation of Duties overview and click to view details.
2. In the details view, click **Edit** to open the Save Query dialog.
3. On the Save Query > Details tab, click the **Labels** dropdown to add one or more labels or start entering text to create a label.
4. Click **Save Query** at the top right after making your changes.

Recommendations:

* Apply a general label like `separation_of_duties` to generally identify all SoD rules.
* Additionally, label the business process associated with each query, e.g., `expenditure` or `revenue`.
* While you can label the data source (identity source or target applications) associated with an SoD query, Veza provides built-in filters for sorting by integration.

#### Setting Up Alerts and Automation

Administrators can configure alerts to trigger when a new user is detected with conflicting roles or permissions. Alerts can trigger email notifications, custom automations with webhooks, or use built-in integrations to create service tickets. Rules for SoD queries can be configured to trigger different actions at different levels of severity.

1. On the Separation of Duties page, filter or search to find a query. Click **Manage Rules** from the actions menu to edit rules for the query.
2. Click *Add a new rule* to open the rule builder:
3. Give the rule a name and description, and set the severity level.
   1. You can configure escalating levels of rules to trigger different actions based on the severity level: High, Medium, or Low.
4. Choose to trigger the rule based on the number of Query Results, or changes in Query Properties. Typically you will want to alert when the query results increase by more than one.
5. Configure rule actions (optional): Check the box to deliver the alert via the selected Veza Action: email, webhook, ServiceNow, or Jira, or create a new Veza Action. The alert will include details about the query result that triggered the rule for remediation purposes.
6. Click *Next* to optionally configure [On-Demand Reviews](/4yItIzMvkpAvMVFAamTf/features/access-reviews/configuration/on-demand-reviews.md) when the results change.
7. Click *Save* to close the rule builder.
8. On the *Save Query* flow, add additional rules as desired.
9. Click *Save Query* to save your changes.

You can review all configured rules for a query on the **Separation of Duties** page by clicking to to open the **Query Details** > **Rules** tab. The **Query Details** > **Alerts** tab will show a log of events for each time a rule triggers.

See [Rules and Alerts](/4yItIzMvkpAvMVFAamTf/features/insights/rules-and-alerts.md) for more information about enabling conditional alerts to trigger automation and notifications when new violations are detected.

### Continuous Monitoring

#### Query Result Details and Change Tracking

The **Separation of Duties** overview page indicates the last update time for each query and the user who modified the query. SoD queries updated via an API key indicate this with `(via API)` in the "last updated by" column. Review these regularly to ensure that SoD rules are not changed unless required.

![Information about query changes on the SoD overview page.](https://1967633068-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZDkWMxox3pekd0NsZJ%2Fuploads%2Fgit-blob-9baf0c84ead922ed2810d380998747cdba8316ef%2FSoD-created-updated-overview.png?alt=media)

Clicking on a query to open the details view shows additional information about the user who created the query and the creation and last update timestamps:

![Creation and modification dates in Query Details view](https://1967633068-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZDkWMxox3pekd0NsZJ%2Fuploads%2Fgit-blob-c8abd3ed13dbfc780aeda8323316baa6c1dc0c44%2FSoD-created-updated-details.png?alt=media)

**Query Edit History**

You can track when SoD queries were last updated using the **Edit History** sidebar in **Query Details**. This can provide historical context about who made changes and when they occurred.

To access the edit history:

1. Open an SoD query to view details
2. Choose **View Edit History** from the query actions

The edit history chronologically shows all changes to date, which can include the original query creation and any modifications to:

* Query name, description, or labels
* Risk levels, risk explanation, or risk remediation
* SoD manager assignments
* Changes to query visibility or query parameters

The edit history will also indicate if changes were made via API (using a [Veza API key](/4yItIzMvkpAvMVFAamTf/developers/api/authentication.md)).

#### Creating Dashboards for Monitoring

While the **Separation of Duties** overview page offers quick visibility into the status of all your SoD queries, you can use [Dashboards](/4yItIzMvkpAvMVFAamTf/features/insights/dashboards.md) to group and track specific queries, getting immediate visibility into trends, top risks, and sharing views with team members.

1. Open **Dashboards** from the Featured section of the navigation sidebar.
2. Click **Create Dashboard** in the Dashboard Library.
3. Give the dashboard a name and description, set visibility, and assign owners.
4. Add sections and include your SoD queries.
5. Click **Save** to create the dashboard, then star it for easy access.

#### Create SoD Dashboards with Sections

You can organize SoD queries into a custom dashboard with sections for different risk areas:

1. Open **Dashboards** from the Featured section of the navigation sidebar.
2. Click **Create Dashboard**.
3. Give the dashboard a name and description.
4. Set the **Visibility** to public or private, and assign owners.
5. Add **Sections** to organize queries by category (e.g., "Financial Controls", "Infrastructure Access").
6. Within each section, click **Add Queries** to search for SoD queries by name, integration, labels, or risk level.
7. Click **Save** to create the dashboard.

After saving, open the dashboard and click the star icon to add it to your favorites for quick access.

{% hint style="info" %}
**Legacy Reports experience**: If your tenant still shows **Reports** under Access Intelligence, see [Reports (Legacy)](/4yItIzMvkpAvMVFAamTf/features/insights/dashboards/reports.md) for the previous workflow. The Reports experience is being consolidated into Dashboards.
{% endhint %}

#### SoD Manager Assignment

You can assign a manager to an SoD to distinguish between query creators and those responsible for managing SoD policies.

* Any SoD query can have one or more managers assigned, for shared responsibility and continuous oversight.
* You can add managers to one or more queries in bulk on the **Separation of Duties** overview page.

To assign SoD managers to queries:

1. On the **Separation of Duties** overview, click the **Assign SoD Manager** button
2. Select one or more queries using the checkboxes on the left
3. In the assignment modal that appears, select one or more users by name or email to assign as managers
4. Review your selections in the "Selected SoD managers" list
5. Click **Save** to apply the assignments

For more details on SoD manager assignment and best practices, see [SoD Manager Assignment](/4yItIzMvkpAvMVFAamTf/features/separation-of-duties/sod-manager-assignment.md).

### Remediation

#### Viewing Conflicting Roles and Permissions

You can review conflicting roles and permissions in Query Builder using the **Show \[Destination Entities]** option. This will display a unique row for each source -> destination relationship in the results, which you can compare to help identify the most appropriate remediation actions.

![SoD risks in Query Builder](https://1967633068-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZDkWMxox3pekd0NsZJ%2Fuploads%2Fgit-blob-f7d59fe47f46fe760aa88433320b4e64cb910765%2FSoD-query.png?alt=media)

For example, if a user in the results has one role in Coupa and another role in Salesforce, the Query Builder wll show a row for the User > Coupa Role relationships, and another row for the User > Salesforce Role relationship.

* Use the *Permissions* column to see both the configured system-level permissions for applicable relationships, and the effective permissions generated by Veza.
* Use the *Destination* columns to show any attributes Veza has discovered for the related role, resource, or other entity.

See [Analyzing Separation of Duties Query Results](/4yItIzMvkpAvMVFAamTf/features/separation-of-duties/analyzing-results.md) for more information.

#### Mapping Mitigating Controls Per Query

When you assign a Risk Level to an SoD query, two built-in fields are available for documenting risk explanations and logging mitigating procedures and/or controls:

* **Risk Explanation**: Use this field to explain the risk. To maintain a consistent style across SoD risks, you can begin with an "If" statement, for example: `If this conflict exists, an individual can enter a fictitious payment and reconcile the cash account, thus resulting in cash position manipulation.`
* **Risk Remediation**: Use this field to record mitigating procedures or controls for SoD risks. This might include the control ID or a brief description of the procedure or control.

These fields support markdown syntax for rich text formatting, including support for hyperlinks.

To add metadata to an SoD query, ensure the query is assigned a risk level, then complete the “Risk Remediation” and “Risk Explanation” fields. You can do this by editing or saving a query:

1. On the **Separation of Duties** overview page, click on a query to view details.
2. In the details view, click **Edit**.
3. In the **Details** > **Risk Level** section, choose a risk level: `Low`, `Medium`, `High`, or `Critical`.
4. Use the text boxes to enter the risk remediation or explanation text.
5. Click **Save Query** at the top right.

To see the explanation or remediation text, open an SoD query to show the details view:

![Risk explanation and remediation in Query Details view.](https://1967633068-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F-MZDkWMxox3pekd0NsZJ%2Fuploads%2Fgit-blob-074d7ca4e484913a27daf19817e830811e3af88b%2FSoD-explanation-remediation-details.png?alt=media)

#### Logging Notes at User Level

When a query is assigned a risk level, entities in the results can have additional notes for documenting mitigations and adding context at the user level. These can be useful for edge cases where a conflict is expected, or a unique mitigating procedure is in place.

You can add two types of notes when viewing risks in Veza:

* Risk Notes: This is a free text note section. You can use this field to document the exact entitlement to remove, when remediation will take place, or if an issue is under investigation.
* Suppression Reasons: After making an exception for a risk, use this field to document the justification why this user is not a violation, or mitigating procedures/controls which are specific for this user

Use the **Query Details** > **Risks** tab to view and add annotations to individual users:

1. On the **Risks** tab, search for the entity where you want to add a note or mark an exception.
2. Expand the row actions menu to choose an action:
   1. **Mark Exception**: Use this option to mark a risk as ignored ("suppressed"), and describe the reason. You can show or hide exceptions on the list of Risks using the **Show Exceptions/Risks** dropdown menu.
   2. **Add Note**: Use this option to note if remediation is planned or record details about the specific violation.

#### Export Capabilities

You can download the results of SoD queries in CSV format for audits, reporting, and analysis. Query exports include:

* A row for each user in the query results, including all attributes Veza has gathered or generated for the user.
* Data source information such as the last extraction time.
* (When exporting Risks) Risk metadata such as if the risk is marked as an exception (suppressed) and the risk assignee.

Veza supports bulk export and scheduled export for SoD queries, as well as support for exporting risk details for query results.

#### Bulk Export

Use the **Separation of Duties** overview tab to export the results of up to ten queries at a time:

1. Click the **Export** button above the list of queries.
2. Use the checkboxes on the left to select queries.
3. Click **Export** again to start the export.

Note that a unique CSV file is generated for each query.

#### Scheduled Export

To enable recurring exports via email or database integration for a single query:

1. Find a query on the **Separation of Duties** overview and choose Actions > Schedule Export.
2. On the **Save Query** screen, choose an export format (CSV by email, or a supported database).
3. Choose the days of the week and time of day to trigger exports.
4. Click **Save Query**.

See [Exporting Saved Query Results to Snowflake](/4yItIzMvkpAvMVFAamTf/integrations/integrations/snowflake/export-to-snowflake.md) for more details about exporting results in tabular format.

#### Export using the Query Details > Risks tab

For SoD queries assigned a risk level, you can export a detailed table of users, including risk metadata such as the assignee, notes, and exception status:

1. Click on an SoD query to view details.
2. Go to the **Query Details** > **Risks** tab.
3. Click the **Export** icon and choose CSV or PDF export.

The exported columns are `Node ID,Risk,Risk Level,Query Name,Node Type,Exception,Time Triggered,Suppressed Reason,Owner Email,Notes`.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.veza.com/4yItIzMvkpAvMVFAamTf/features/separation-of-duties/manage-sod-risks-with-veza.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
