Announcing the Saviynt Knowledge Exchange unifying the Saviynt forums, documentation, training,
and more in a single search tool across platforms. Read the announcement here.

SOD review and mitigation controls at 2nd level in the approval workflow

rgupta34
New Contributor
New Contributor

Hello ,

 

At our client, we have a 3 level workflow already in place (Manager --> Business Owner --> CISO) depending on the criticality of the entitlement.

We have now implemented SOD's and mitigation controls and added additional level of approval at the workflow level i.e. (Manager --> SOD approval/review and apply mitigation control --> Business Owner --> CISO) and we have the following questions w.r.t feasibility of this workflow -- 

1. Is the manager allwed to simply see all entitlements requested and take action(approve/reject) and pass it to second level i.e. SOD reviewer to apply mitigation controls

2. can SOD review and process to apply mitigation control happen at second stage (and not at first level )- and what are the actions SOD reviewer can take : is it approve/reject or apply mitigation controls?

3. After applying mitigation controls at second level , will the request proceed to next levels and get completed once all the approvals are done?

2 REPLIES 2

dgandhi
All-Star
All-Star

1. Is the manager allwed to simply see all entitlements requested and take action(approve/reject) and pass it to second level i.e. SOD reviewer to apply mitigation controls

--> Yes

2. can SOD review and process to apply mitigation control happen at second stage (and not at first level )- and what are the actions SOD reviewer can take : is it approve/reject or apply mitigation controls?

--> I believe yes

3. After applying mitigation controls at second level , will the request proceed to next levels and get completed once all the approvals are done?

--> Yes

Thanks,
Devang Gandhi
If this reply answered your question, please Accept As Solution and give Kudos to help others who may have a similar problem.

rushikeshvartak
All-Star
All-Star
  • 1 Yes ( in workflow block don’t add mitigation control mandatory selection)
  • 2  They can approve / reject and also attach mitigation control
  • 3 until all mitigation control applied request will not come to step 3 ( based on configuration in workflow and risk priority) hence step 3 can appove/ reject seeing mitigation controls 

workflow configs ( mc required on risk 

rushikeshvartak_0-1711120979450.png

 


Regards,
Rushikesh Vartak
If you find the response useful, kindly consider selecting Accept As Solution and clicking on the kudos button.