MAINTENANCEHR record change in progress
Active case · loading…
I

Identity

stands in for · Okta / Active Directory (IAM)
Who may approve — SOX segregation-of-duties

Console operator

No operator is currently signed in — pull/verify actions fall back to a generic actor. Sign in ↗

Who may approve?

The lookup ApprovalFlow makes on every submission — surfaced here for the operator to run by hand: which authorised approver is not the request owner (SOX SoD).

SoD decision — WF-INCENTIVE-STD

Request owner excluded from approval: (none supplied)

Approver assigned
R. Delgado · r.delgado
Control
SoD ok
Decision logic
Identity selected the first workflow-authorised candidate who is not the request owner.

Candidate-by-candidate evidence

CandidatePrincipal IDAuthenticated rolesCurrent result
R. Delgado r.delgado payroll_reviewer, payroll_approver, esign_authorizer eligible — authorised and independent
V. Osei victor.osei comp_approver, payroll_approver, esign_authorizer eligible — authorised and independent

Used next: ApprovalFlow receives the resolved principal ID and independently requires a signed token with an authorised approval role before recording a vote.

Approver entitlements

Segregation-of-duties directory. ApprovalFlow asks this service who may approve a given workflow and enforces that the approver ≠ the request owner. This is what turns "a human approved it" into a defensible SOX control — automation preserves it, never bypasses it.

Open a person to see their principal ID, authenticated roles, workflow entitlements, and direct operations for testing the SoD control.

R. Delgado · Payroll Ops Manager eligible for selected workflow
Principal ID
r.delgado
Directory role
Payroll Ops Manager
Authenticated token roles
payroll_reviewer, payroll_approver, esign_authorizer
Authorised approval workflows
WF-TERMINATION-DUAL WF-CORRECTION-DUAL WF-STANDARD-SINGLE WF-INCENTIVE-STD

Run the control: Resolve WF-TERMINATION-DUAL · Resolve WF-CORRECTION-DUAL · Resolve WF-STANDARD-SINGLE · Resolve WF-INCENTIVE-STD

Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.

V. Osei · Comp & Finance Director eligible for selected workflow
Principal ID
victor.osei
Directory role
Comp & Finance Director
Authenticated token roles
comp_approver, payroll_approver, esign_authorizer
Authorised approval workflows
WF-INCENTIVE-STD WF-TERMINATION-DUAL WF-STANDARD-SINGLE

Run the control: Resolve WF-INCENTIVE-STD · Resolve WF-TERMINATION-DUAL · Resolve WF-STANDARD-SINGLE

Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.

L. Fenwick · Controller not entitled to selected workflow
Principal ID
l.fenwick
Directory role
Controller
Authenticated token roles
controller, payroll_approver, esign_authorizer
Authorised approval workflows
WF-CORRECTION-DUAL WF-TERMINATION-DUAL

Run the control: Resolve WF-CORRECTION-DUAL · Resolve WF-TERMINATION-DUAL

Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.

Nora Patel · Finance Controller not entitled to selected workflow
Principal ID
nora.patel
Directory role
Finance Controller
Authenticated token roles
controller, payroll_approver
Authorised approval workflows
WF-CORRECTION-DUAL WF-TERMINATION-DUAL WF-STANDARD-SINGLE

Run the control: Resolve WF-CORRECTION-DUAL · Resolve WF-TERMINATION-DUAL · Resolve WF-STANDARD-SINGLE

Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.

Human principal directory

Inspectable identity labels only. Authentication still requires a signed, short-lived token; token values and the signing secret are never shown here.

Principal IDNameRolesApproval directory
maya.chenMaya Chencomp_makernot an approver
victor.oseiV. Oseicomp_approver, payroll_approver, esign_authorizerentitled
r.delgadoR. Delgadopayroll_reviewer, payroll_approver, esign_authorizerentitled
l.fenwickL. Fenwickcontroller, payroll_approver, esign_authorizerentitled
nora.patelNora Patelcontroller, payroll_approverentitled
nadia.chenNadia Chenhr_admin, esign_authorizernot an approver
samir.patelSamir Patelprovider_operatornot an approver
partner.northwindNorthwind Partner APIintake_submitternot an approver

API

GET /api/approver
?workflow=&exclude=<owner> → authorised approver + sod_ok flag
💬
00:00 manual timer
Cases