Flagship course

API SoD Control Matrix

Build financial auditing guidance into a working segregation-of-duties matrix for API-driven accounting—privileges, conflicts, compensating controls, and evidence in one artifact.

Team collaborating during a workshop session

Learning outcomes

What you can defend after the defense session

  • Catalog human and machine principals against posting verbs
  • Maintain a conflict library for create / approve / configure paths
  • Document compensating controls when splits are delayed
  • Assemble a sampling-ready webhook and access evidence pack
  • Write remediation tickets engineers will accept into a sprint
  • Narrate the matrix for a Korea-oriented external walkthrough

Modules

Eight weeks, one living matrix

1 · API-era SoD vocabulary

Translate classic duty labels into endpoint verbs and identity types without losing auditor meaning.

2 · Privilege dumps that survive review

Import and normalize role exports, OAuth scopes, and service accounts into a catalog you can diff between releases.

3 · REST verb maps and high-risk pairs

Build the conflict library for posting, approving, reversing, and mutating standing data.

4 · Service accounts and CI bots

Treat pipelines as principals. Split deploy rights from posting rights with patterns that fit common Korean mid-market stacks.

5 · Webhook evidence packs

Decide which delivery logs, signatures, and retry trails belong in an external audit sample.

6 · Compensating controls that are not theater

Time-boxed break-glass, dual subscribers, and immutable stores—when each is honest enough to cite.

7 · Remediation language for engineering

Rewrite findings as tickets with owners, acceptance criteria, and residual risk notes.

8 · Defense session

Present your matrix to a mock reviewer. Receive annotated critique you can reuse with real stakeholders.

Instructor

Who facilitates the labs

Portrait of course instructor

Eun-ji Hahn

Former internal audit manager turned controls educator. Eun-ji has facilitated thirty-plus cohorts focused on segregation of duties where ledgers post through partner APIs and shared service accounts. She co-wrote the sample conflict library used across Smart Auto APIs programs.

Pricing (informational)

Control Matrix Studio seat

₩890,000 / learner

Includes live labs, peer review, defense session, and 90-day alumni forum. Invoiced after intake—no checkout on this site. See all tiers and refund terms.

Request enrollment
Notebook and analytics worksheets on a desk

FAQ

Straight answers

Do I need an engineering background?

No, but you need access to someone who can export privileges or scopes. Finance-only learners pair well with a platform buddy for Modules 4 and 5.

Will you map our exact ERP connector?

We provide patterns and a Korea-market sample set. We do not deliver a turnkey matrix for every vendor API—that remains your artifact. Private Audit Lab Intensives go deeper on your dump.

What is a real limitation of this course?

We do not cover GraphQL-heavy ledgers in depth. Teams on GraphQL spend extra time adapting the REST verb map, and that adaptation is not graded as a separate module.

Is there a certificate?

You receive a completion letter describing the defense session. It is not a regulated credential and should not be marketed as one.

Course reviews

From recent Control Matrix Studio seats

“Module 4 on CI bots is where we found our quiet failure: deploy and post shared a key. Fix took a week; finding it took the lab.”
Platform engineer · Seoul cohort
“Evidence pack format from Module 5 is now our default appendix. I wish the GraphQL note in the FAQ had been louder before we enrolled—we burned two evenings adapting verbs.”
Nari · Internal audit · Gwangju