Skip to content

Handling Policy Violations

By creating your first separation of duties (SoD) policies, you've taken some proactive steps to keeping your organization safe.

Next, you'll track open violations on those policies and mitigate violations with controls.

Viewing SoD Violations

Admins, SoD Violations Admins, and SoD Compliance Officers can view a list of SoD policy violations. Note that there are multiple risk levels for SoD policies, and violations to those policies inherit the same risk level as the policy violated.

Tip

Violation Owners can use the tile on MySailPoint to go to open violations that they are responsible for.

  1. Go to Admin > SoD Policies.
  2. On the left navigation, select Policy Violations.
  3. You can filter the list of violations by policy name, identity, violation owner, or level. Quick filters are also available for All, Open, and Mitigated violations.
  4. Select a specific violation to view its details, such as identity email, policy violated, policy description, status, expiration, policy level, and a list of specific conflicts. If the violation has been mitigated, details about that mitigation are also included.

Mitigating SoD Violations

Admins and SoD Violations Admins can mitigate SoD policy violations from the Policy Violations page.

  1. Go to Admin > SoD Policies.
  2. On the left navigation, select Policy Violations.
  3. You can filter the list of violations by policy name, identity, violation owner, or level. Quick filters are also available for All, Open, and Mitigated violations.
  4. Select a specific violation to view its details, such as identity email, policy violated, policy description, status, expiration, policy level, and a list of specific conflicts. If the violation has been mitigated, details about that mitigation are also included.
  5. Select Mitigate.
  6. Select a mitigating control to address the policy conflict.
  7. Add comments about the mitigation.
  8. Select Apply.

SoD Violation Event Triggers

SoD event triggers are available for elements of the SoD violation lifecycle, when an SoD violation is created, mitigated, reopened and closed. Refer to Using Event Triggers.

Documentation Feedback

Feedback is provided as an informational resource only and does not form part of SailPoint’s official product documentation. SailPoint does not warrant or make any guarantees about the feedback (including without limitation as to its accuracy, relevance, or reliability). All feedback is subject to the terms set forth at https://developer.sailpoint.com/discuss/tos.