Regarding Apptio Cost Transparency (CT) exclusively, does your company apply SOX controls? If yes, why and to what degree?
My opinion...
All authenticated users found in the Identity Access Managment (IAM) system should be permitted, at minimum, View Only (or its equivalent) role access.
If necessary, when Apptio CT has matured enough to expand access beyond the core TBM Team, Finance Partners, C Suite and directs, and Budget Owners (including their proxies)...policies should be put into place to define roles and how a person is granted a role. This was proven unnecessary at a past employer 10x's as large as where I'm at now. Hence, why I start out with "if necessary". ;-)
I am not in favor of managing users' access exclusively via Apptio CT or Frontdoor when there is an IAM system in production.
I don’t regard Apptio CT as a “financial system” subject to SOX for these reasons:
- It does not record financial transactions
- It is not a source system for reports published to the Street
- It does not perform financial/accounting data entry
- It does not affect the accounting system of record
- It does not perform budget/forecasting data entry
- It does not affect the budget/forecasting system of record
- Any changes to a system of record would require a person to work with / contact a qualified person (eg Accounting, Finance Partner, HR, etc) to initiate change via established governed processes.
And, Apptio CT does not perform data entry of HR, PIM, Clarity, etc related information. Yes, it does provide persons with configuration abilities to revise values to present the data onto its reports, but the key is source systems of record are unchanged and cannot be changed via Apptio CT.
This has been a lingering concern of mine for years, so I'm naturally eager to see/hear from others on the subject.
Lastly, I'm not saying my approach or opinions are right. I'm just tossing them out there for validation and to get the conversation started. ;-)