Skip to content

Process Manipulation

Process manipulation exploits weak, informal, unclear, overloaded, or poorly enforced organisational processes. The attacker may seek a bypass, misuse an exception, alter an approval sequence, exploit unclear ownership, insert a changed action into a real workflow, or supply false evidence that a process has already occurred.

The request often appears administrative rather than security-sensitive. A payment change, access request, ticket update, hand-off, or approval may be framed as routine completion of work that someone else has already checked. The process itself then carries legitimacy into an action that lacks the required authority or evidence.

Process manipulation can be assessed by asking:

  • Which process or decision path is being used?
  • What step, owner, approval, evidence, or system of record is being bypassed or misrepresented?
  • Is the exception or changed sequence authorised for this situation?
  • Can the request be confirmed within the established workflow?

Process Manipulation includes the techniques below. Select a technique to open its behavioural method, common examples, relevant taxonomy boundaries, and control-domain orientation in the Technique Catalogue.


Process manipulation activity may involve one or more of the following behaviours:

Workflow and approval behaviour

  • requesting exceptions to normal process
  • asking for manual handling, workaround, override, or direct approval
  • claiming a process is blocking urgent, important, or routine work
  • presenting a risky request as administrative, ordinary, already approved, or low-impact
  • referencing previous approval without evidence
  • asking for approval after the action has already started or been completed

Ownership and handoff behaviour

  • exploiting unclear ownership or approval paths
  • creating ambiguity around responsibility, authority, or process state
  • contacting multiple departments to find the weakest point in a handoff
  • claiming another team, manager, supplier, customer, or system owner is responsible for the request
  • using “finance said IT handles it” or “HR told me to contact you” style handoff pressure
  • pushing staff to resolve ambiguity quickly rather than confirm process ownership

Identity, access, supplier, and asset behaviour

  • targeting access provisioning, onboarding, reactivation, role-change, temporary-access, or privileged-access workflows
  • requesting supplier bank detail changes, payroll changes, invoice updates, or payment redirection
  • using tickets, forms, workflow references, or approval language to create legitimacy
  • supplying forged, doctored, recycled, or fabricated documents, screenshots, ticket numbers, or approval references that cannot be validated in the system of record

Pressure and control-fatigue behaviour

  • targeting busy periods, queues, incidents, payroll runs, finance cut-offs, enrolment windows, holidays, or after-hours conditions
  • pressuring staff to “just do it this once”
  • resisting ticket creation, workflow entry, callback, second approval, or documented verification
  • escalating when the target attempts to follow process
  • exploiting helpfulness, urgency, authority, familiarity, or confusion to bypass checkpoints