Flagship course
API SoD Control Matrix
Build financial auditing guidance into a working segregation-of-duties matrix for API-driven accounting—privileges, conflicts, compensating controls, and evidence in one artifact.
Learning outcomes
What you can defend after the defense session
- Catalog human and machine principals against posting verbs
- Maintain a conflict library for create / approve / configure paths
- Document compensating controls when splits are delayed
- Assemble a sampling-ready webhook and access evidence pack
- Write remediation tickets engineers will accept into a sprint
- Narrate the matrix for a Korea-oriented external walkthrough
Modules
Eight weeks, one living matrix
1 · API-era SoD vocabulary
Translate classic duty labels into endpoint verbs and identity types without losing auditor meaning.
2 · Privilege dumps that survive review
Import and normalize role exports, OAuth scopes, and service accounts into a catalog you can diff between releases.
3 · REST verb maps and high-risk pairs
Build the conflict library for posting, approving, reversing, and mutating standing data.
4 · Service accounts and CI bots
Treat pipelines as principals. Split deploy rights from posting rights with patterns that fit common Korean mid-market stacks.
5 · Webhook evidence packs
Decide which delivery logs, signatures, and retry trails belong in an external audit sample.
6 · Compensating controls that are not theater
Time-boxed break-glass, dual subscribers, and immutable stores—when each is honest enough to cite.
7 · Remediation language for engineering
Rewrite findings as tickets with owners, acceptance criteria, and residual risk notes.
8 · Defense session
Present your matrix to a mock reviewer. Receive annotated critique you can reuse with real stakeholders.
Instructor
Who facilitates the labs
Eun-ji Hahn
Former internal audit manager turned controls educator. Eun-ji has facilitated thirty-plus cohorts focused on segregation of duties where ledgers post through partner APIs and shared service accounts. She co-wrote the sample conflict library used across Smart Auto APIs programs.
Pricing (informational)
Control Matrix Studio seat
₩890,000 / learner
Includes live labs, peer review, defense session, and 90-day alumni forum. Invoiced after intake—no checkout on this site. See all tiers and refund terms.
Request enrollmentFAQ
Straight answers
Do I need an engineering background?
No, but you need access to someone who can export privileges or scopes. Finance-only learners pair well with a platform buddy for Modules 4 and 5.
Will you map our exact ERP connector?
We provide patterns and a Korea-market sample set. We do not deliver a turnkey matrix for every vendor API—that remains your artifact. Private Audit Lab Intensives go deeper on your dump.
What is a real limitation of this course?
We do not cover GraphQL-heavy ledgers in depth. Teams on GraphQL spend extra time adapting the REST verb map, and that adaptation is not graded as a separate module.
Is there a certificate?
You receive a completion letter describing the defense session. It is not a regulated credential and should not be marketed as one.
Course reviews
From recent Control Matrix Studio seats
“Module 4 on CI bots is where we found our quiet failure: deploy and post shared a key. Fix took a week; finding it took the lab.”Platform engineer · Seoul cohort
“Evidence pack format from Module 5 is now our default appendix. I wish the GraphQL note in the FAQ had been louder before we enrolled—we burned two evenings adapting verbs.”Nari · Internal audit · Gwangju