Over-provisioned standing access
Toxic combination
Also called: segregation-of-duties conflict
A toxic combination is a set of permissions that is safe when split between people but risky when one identity holds all of them, such as creating a vendor and approving its payments. It breaks segregation of duties, so a single compromised or dishonest account can complete a sensitive process without anyone else checking it.
How it works
Conflicting rights usually arrive separately, through role changes, emergency grants or broad roles that bundle too much. Each grant looks reasonable alone, so the conflict goes unnoticed unless someone checks combinations. An attacker or insider using that account can then initiate and approve the same action, leaving no second person positioned to catch it.
A real example
A December 2020 Treasury Office of Inspector General management letter reported that the Alcohol and Tobacco Tax and Trade Bureau had ten users with incompatible or conflicting roles or access in a system for processing certain tax transactions.
Source: Management Letter for the Audit of the Alcohol and Tobacco Tax and Trade Bureau's Financial Statements for Fiscal Years 2020 and 2019 (OIG-21-017) — US Department of the Treasury, Office of Inspector General, 2020-12-15
How to stop it
Define the permission pairs that must never sit on one identity, block them at provisioning time, and include them in every access review.
Related terms
Sources
- Management Letter for the Audit of the Alcohol and Tobacco Tax and Trade Bureau's Financial Statements for Fiscal Years 2020 and 2019 (OIG-21-017) — US Department of the Treasury, Office of Inspector General, 2020-12-15
Last reviewed Oct 2, 2026