Insights

Notes on SAP security, risk & control

Practical thinking on SAP security, governance, risk and compliance, access risk, segregation of duties, privileged access, role design and audit readiness.

Thought LeadershipJune 2026

GRC in the S/4HANA migration: rebuild, don't carry forward

The migration is the rare chance to fix years of access debt. Why copying roles forward wastes it, and where agentic AI changes the economics.

Read →
Sensitive AccessMay 2026

Sensitive access: the risk that isn't a conflict

Segregation of duties gets the attention, but some of the most dangerous access needs no second person and no conflict, just one powerful action.

Read →
Audit ReadinessApril 2026

Making user access reviews actually mean something

Rubber-stamped recertification is worse than none at all. How to turn access reviews from a compliance chore into a real control.

Read →
Privileged AccessMarch 2026

Firefighter access that auditors trust

Emergency access is necessary and dangerous in equal measure. How to design privileged access that keeps the business moving and the auditors satisfied.

Read →
Role DesignFebruary 2026

Business roles without the baggage

Why most SAP role models drift into chaos, and how to build a least-privilege design that stays clean and maintainable for years.

Read →
Access Risk AnalysisJanuary 2026

Where SAP access risk actually hides, and how to find it

Most access risk doesn't sit in obvious places. A practical look at how to surface the segregation-of-duties and sensitive-access exposure that audits miss.

Read →