MAINTENANCEHR record change in progress
Active case · loading…
I

Identity

stands in for · Okta / Active Directory (IAM)
Who may approve — SOX segregation-of-duties

Console operator

No operator is currently signed in — pull/verify actions fall back to a generic actor. Sign in ↗

Who may approve?

The lookup ApprovalFlow makes on every submission — surfaced here for the operator to run by hand: which authorised approver is not the request owner (SOX SoD).

Approver entitlements

Segregation-of-duties directory. ApprovalFlow asks this service who may approve a given workflow and enforces that the approver ≠ the request owner. This is what turns "a human approved it" into a defensible SOX control — automation preserves it, never bypasses it.

Open a person to see their principal ID, authenticated roles, workflow entitlements, and direct operations for testing the SoD control.

R. Delgado · Payroll Ops Manager Open principal details
Principal ID
r.delgado
Directory role
Payroll Ops Manager
Authenticated token roles
payroll_reviewer, payroll_approver, esign_authorizer
Authorised approval workflows
WF-TERMINATION-DUAL WF-CORRECTION-DUAL WF-STANDARD-SINGLE WF-INCENTIVE-STD

Run the control: Resolve WF-TERMINATION-DUAL · Resolve WF-CORRECTION-DUAL · Resolve WF-STANDARD-SINGLE · Resolve WF-INCENTIVE-STD

Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.

V. Osei · Comp & Finance Director Open principal details
Principal ID
victor.osei
Directory role
Comp & Finance Director
Authenticated token roles
comp_approver, payroll_approver, esign_authorizer
Authorised approval workflows
WF-INCENTIVE-STD WF-TERMINATION-DUAL WF-STANDARD-SINGLE

Run the control: Resolve WF-INCENTIVE-STD · Resolve WF-TERMINATION-DUAL · Resolve WF-STANDARD-SINGLE

Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.

L. Fenwick · Controller Open principal details
Principal ID
l.fenwick
Directory role
Controller
Authenticated token roles
controller, payroll_approver, esign_authorizer
Authorised approval workflows
WF-CORRECTION-DUAL WF-TERMINATION-DUAL

Run the control: Resolve WF-CORRECTION-DUAL · Resolve WF-TERMINATION-DUAL

Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.

Nora Patel · Finance Controller Open principal details
Principal ID
nora.patel
Directory role
Finance Controller
Authenticated token roles
controller, payroll_approver
Authorised approval workflows
WF-CORRECTION-DUAL WF-TERMINATION-DUAL WF-STANDARD-SINGLE

Run the control: Resolve WF-CORRECTION-DUAL · Resolve WF-TERMINATION-DUAL · Resolve WF-STANDARD-SINGLE

Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.

Human principal directory

Inspectable identity labels only. Authentication still requires a signed, short-lived token; token values and the signing secret are never shown here.

Principal IDNameRolesApproval directory
maya.chenMaya Chencomp_makernot an approver
victor.oseiV. Oseicomp_approver, payroll_approver, esign_authorizerentitled
r.delgadoR. Delgadopayroll_reviewer, payroll_approver, esign_authorizerentitled
l.fenwickL. Fenwickcontroller, payroll_approver, esign_authorizerentitled
nora.patelNora Patelcontroller, payroll_approverentitled
nadia.chenNadia Chenhr_admin, esign_authorizernot an approver
samir.patelSamir Patelprovider_operatornot an approver
partner.northwindNorthwind Partner APIintake_submitternot an approver

API

GET /api/approver
?workflow=&exclude=<owner> → authorised approver + sod_ok flag
💬
00:00 manual timer
Cases