← All case studies
Media / Telecom
In production since 2014 · Cloud upgrade 2021
Upgraded to cloud/Fiori 2021

Grupa Polsat Plus: 3,500 users across 14 systems

One of Poland's largest media and telecom groups - Cyfrowy Polsat + Polkomtel - runs smartGRC across SAP ECC, EWM, APO, HCM and more. Originally deployed in November 2014 for SoD monitoring and emergency access, upgraded to cloud/Fiori-based architecture in 2021. The story below describes the original 2014 implementation.

Industry
Media / Telecom
Scale today
3,500 users, 14 systems
SAP estate
SAP ECC (Cyfrowy Polsat + Polkomtel), EWM, APO, HCM
Modules
All smartGRC modules
timeline
Today (2026)

3,500 users · 14 systems · all smartGRC modules

From the original 300-user Cyfrowy Polsat ECC deployment in 2014, the smartGRC footprint at Grupa Polsat Plus has grown to 3,500 SAP users across 14 systems - including Cyfrowy Polsat ECC, Polkomtel ECC, SAP EWM, APO and HCM. In 2021, the platform was upgraded to a cloud / Fiori-based architecture, replacing the original deployment with a modern, scalable foundation while preserving the operational continuity built up over 10+ years.

The story below describes the original 2014 implementation for Cyfrowy Polsat - the foundation that grew into the multi-entity Grupa Polsat Plus deployment.

Modules deployed in 2014:
smartSoD smartAccess smartWorkflow

The Challenge

Cyfrowy Polsat - one of the largest media and telecom groups in Poland with millions of customers - needed two things from SAP access governance. First, ongoing identification and analysis of Segregation of Duties (SoD) risks embedded in user and role authorizations defined in SAP. Second, a controlled, fully auditable way to manage emergency (firefighter) access accounts that hold broad SAP system access. The scope spanned finance, purchasing, sales, production planning and execution, material management and quality assurance.

The Solution

smartSoD reporting provided identification and analysis of SoD risks and conflicts embedded in users and role authorizations defined in SAP. The data synchronization mechanism downloaded data from SAP to the local application server, with extended reporting capabilities allowing presentation in different dimensions (user or role) and different levels of detail.

smartAccess (firefighter workflow) managed emergency access accounts in a controlled, audit-ready way. Every action during emergency sessions was logged automatically - data changes, table modifications, program execution. For audit purposes, the application generated detailed control evidence documentation from each control execution performed by the responsible oversight person.

Business activities were mapped to corresponding authorization-level customization objects in SAP. The emergency access workflow is used by 15 people from technical and business supporting departments. SoD risks and conflicts monitoring is executed for all 300 users in SAP ECC.

The Results

300
SAP users continuously monitored for SoD risk
8 weeks
Technical installation + implementation
15 people
Use firefighter workflow with full audit trail
format_quote
"Security & Compliance application has been implemented by GRC Solutions and is in production use since November 2014 at Cyfrowy Polsat. Technical installation and implementation was made in 8 weeks and entire project with detailed process design was done in 12 weeks. Workflow for managing emergency access is being used by 15 people from technical and business supporting departments. Segregation of duties risks and conflicts monitoring is executed for 300 users in SAP ECC system."
Robert Nikołajew
Head of Internal Audit, Cyfrowy Polsat
Signed reference letter, Warsaw, December 1, 2014

Ready for similar results?

See smartGRC running on a sandbox like yours - all modules, 19 AI agents, with your SAP context in mind.