WardeDocs Administrators Connectors People using Warde warde.app

Administrator guide

Separation of duties

How Warde checks a request against your identity engine's separation of duties rules, and the one setting that decides what happens on a conflict.

Warde does not keep its own separation of duties (SoD) rules. Your identity engine holds them, and Warde asks the engine before approval whether the access on a request conflicts with what the person already holds or with the rest of the request.

The setting

One instance-wide setting decides what happens when a conflict is found. Set it in Guided Setup step 6.

When a conflict is foundWhat happens
Warn (the default)Approvers see the conflict and still decide. Warn never stops a request.
BlockThe request line fails before approval, and the requester is told why
OffNothing is checked, and approvers see nothing

Where the check runs decides when the check happens:

Where the check runsMeaning
Both (the default)The Request Access and Access Bundles forms check before submit, and each request line is checked again after submit and before approval
Client side (form)The forms check, and cannot be submitted until everything on them is checked. A line is still checked after submit unless the form checked it and found no conflict, which covers access added because other access needs it.
Server side (approver)Each request line is checked after submit and before approval, and the result is added to the request as a comment

A form check makes people wait for each engine to answer before they can submit.

With Off, the forms do not check, request lines are not checked before approval, and approvers see no conflicts. The engine still applies its own rules when it adds the access.

Which engines answer

EngineChecked before approval
SailPoint IdentityIQYes. Warde asks IdentityIQ's policy check for each request.
SailPoint Identity Security CloudNo. ISC applies its SoD policies itself when it provisions.
Microsoft Entra ID GovernanceNo. Entra has no pre-provisioning conflict check.
ServiceNow tasksNo

For access fulfilled by an engine with no check, the row reads Not checked, and approvers see that.

Where a verdict shows

When the engine does not answer

SettingWhat it doesDefault
x_66256_warde.sod.pending_timeout_minsHow long Warde waits for the engine's answer before acting on the next setting15
x_66256_warde.sod.unavailable_actionproceed lets the line continue, marked as unavailable, and the engine still applies its own rules when it grants; block fails the lineproceed
SettingWhat it doesDefault
x_66256_warde.sod.context_linesHow many of the same person's other open requests are sent with each check, so two pieces of access requested at the same time are checked against each other. Each item in a bundle counts as one.20
x_66256_warde.sod.bundle_member_capThe largest bundle checked before approval. A bigger bundle is marked as not checked, and the engine applies its own rules when it adds the access.40

Warde is a ServiceNow scoped application, x_66256_warde. These guides describe the current release. Questions go to hello@warde.app.

ServiceNow is a trademark of ServiceNow, Inc. SailPoint, IdentityIQ and Identity Security Cloud are trademarks of SailPoint Technologies, Inc. Microsoft and Microsoft Entra are trademarks of the Microsoft group of companies.