US Segregation-of-Duties
Detect conflicting user rights (create-vendor + pay, post-JE + approve), run a remediation worklist and export a SOX audit file.
Detect conflicting user rights (create-vendor + pay, post-JE + approve), run a remediation worklist and export a SOX audit file.
Key Features
Pre-seeded ruleset of classic US SOX / COSO conflicts
create-vendor and pay, post journal entry and approve the close, raise and self-approve purchase orders, enter and pay vendor bills, administer access and disburse cash.
Business functions map one or more Odoo security
Business functions map one or more Odoo security groups onto a single auditable capability, so the ruleset stays readable to non-technical auditors.
One-click conflict scan across all internal users (or
One-click conflict scan across all internal users (or a selected population), honoring implied groups so inherited rights are never missed.
Remediation worklist
every conflict becomes a work item you can assign, review, mitigate with a compensating control, accept with documented rationale, or resolve.
Evidence trail
each finding records the exact security groups on the user that triggered the conflict.
Risk scoring with Low / Medium / High
Risk scoring with Low / Medium / High / Critical weighting and an aggregate exposure score per scan.
Prior dispositions are carried forward on re-scan, so
Prior dispositions are carried forward on re-scan, so remediation history is never lost between quarters.
Optional scheduled scan to keep the conflict population
Optional scheduled scan to keep the conflict population continuously fresh.
Audit export to CSV, filterable by risk level
Audit export to CSV, filterable by risk level and status, ready to attach to SOX workpapers.
Screenshots
Why Choose This Module
Toxic combinations of access rights are the #1 finding in US SOX audits, and they usually stay invisible until an auditor spreadsheets your user list by hand. This application continuously maps Odoo security groups onto auditable business functions, then scans every internal user for conflicting rights against a ruleset of classic US internal-control conflicts.
Specifications
- Compatible: Odoo 18.0 / 19.0
- License: OPL-1
- Languages: English
- Author: Pokutsoft
- Dependencies: base, account, purchase
- Support: support@pokutsoft.com
Update date: 2026-07-05
| Availability |
Odoo Online
Odoo.sh
On Premise
|
| Odoo Apps Dependencies |
•
Invoicing (account)
• Purchase (purchase) • Discuss (mail) |
| Lines of code | 1425 |
| Technical Name |
us_segregation_of_duties_conflict_analyzer |
| License | OPL-1 |
| Website | https://pokutsoft.com |
Odoo Proprietary License v1.0 This software and associated files (the "Software") may only be used (executed, modified, executed after modifications) if you have purchased a valid license from the authors, typically via Odoo Apps, or if you have received a written agreement from the authors of the Software (see the COPYRIGHT file). You may develop Odoo modules that use the Software as a library (typically by depending on it, importing it and using its resources), but without copying any source code or material from the Software. You may distribute those modules under the license of your choice, provided that this license is compatible with the terms of the Odoo Proprietary License (For example: LGPL, MIT, or proprietary licenses similar to this one). It is forbidden to publish, distribute, sublicense, or sell copies of the Software or modified copies of the Software. The above copyright notice and this permission notice must be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
Please log in to comment on this module