Console operator
No operator is currently signed in — pull/verify actions fall back to a generic actor. Sign in ↗
Who may approve?
The lookup ApprovalFlow makes on every submission — surfaced here for the operator to run by hand: which authorised approver is not the request owner (SOX SoD).
SoD decision — WF-STANDARD-SINGLE
Request owner excluded from approval: (none supplied)
Candidate-by-candidate evidence
| Candidate | Principal ID | Authenticated roles | Current result |
|---|---|---|---|
| R. Delgado | r.delgado | payroll_reviewer, payroll_approver, esign_authorizer | eligible — authorised and independent |
| V. Osei | victor.osei | comp_approver, payroll_approver, esign_authorizer | eligible — authorised and independent |
| Nora Patel | nora.patel | controller, payroll_approver | eligible — authorised and independent |
Used next: ApprovalFlow receives the resolved principal ID and independently requires a signed token with an authorised approval role before recording a vote.
Approver entitlements
Segregation-of-duties directory. ApprovalFlow asks this service who may approve a given workflow and enforces that the approver ≠ the request owner. This is what turns "a human approved it" into a defensible SOX control — automation preserves it, never bypasses it.
Open a person to see their principal ID, authenticated roles, workflow entitlements, and direct operations for testing the SoD control.
R. Delgado · Payroll Ops Manager eligible for selected workflow
Run the control: Resolve WF-TERMINATION-DUAL · Resolve WF-CORRECTION-DUAL · Resolve WF-STANDARD-SINGLE · Resolve WF-INCENTIVE-STD
Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.
V. Osei · Comp & Finance Director eligible for selected workflow
Run the control: Resolve WF-INCENTIVE-STD · Resolve WF-TERMINATION-DUAL · Resolve WF-STANDARD-SINGLE
Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.
L. Fenwick · Controller not entitled to selected workflow
Run the control: Resolve WF-CORRECTION-DUAL · Resolve WF-TERMINATION-DUAL
Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.
Nora Patel · Finance Controller eligible for selected workflow
Run the control: Resolve WF-CORRECTION-DUAL · Resolve WF-TERMINATION-DUAL · Resolve WF-STANDARD-SINGLE
Eligibility requires both workflow entitlement and separation from the request owner. This page never displays or accepts a token secret.
Human principal directory
Inspectable identity labels only. Authentication still requires a signed, short-lived token; token values and the signing secret are never shown here.
| Principal ID | Name | Roles | Approval directory |
|---|---|---|---|
| maya.chen | Maya Chen | comp_maker | not an approver |
| victor.osei | V. Osei | comp_approver, payroll_approver, esign_authorizer | entitled |
| r.delgado | R. Delgado | payroll_reviewer, payroll_approver, esign_authorizer | entitled |
| l.fenwick | L. Fenwick | controller, payroll_approver, esign_authorizer | entitled |
| nora.patel | Nora Patel | controller, payroll_approver | entitled |
| nadia.chen | Nadia Chen | hr_admin, esign_authorizer | not an approver |
| samir.patel | Samir Patel | provider_operator | not an approver |
| partner.northwind | Northwind Partner API | intake_submitter | not an approver |
API
GET /api/approver