Tanzu Application Service (TAS for VMs) provides basic RBAC support. Enforcement of separation of duties (SOD) is the responsibility of the deployer.
TAS for VMs supports assignment of specific roles so that users may be given separate duties as appropriate. Granularity of permission set in a defined role is fixed. Additional controls may be inherited from systems external to TAS for VMs.
The organization:
Separation of duties addresses the potential for abuse of authorized privileges and helps to reduce the risk of malevolent activity without collusion. Separation of duties includes, for example: (i) dividing mission functions and information system support functions among different individuals and/or roles; (ii) conducting information system support functions with different individuals (e.g., system management, programming, configuration management, quality assurance and testing, and network security); and (iii) ensuring security personnel administering access control functions do not also administer audit functions.