One of Poland's largest media and telecom groups - Cyfrowy Polsat + Polkomtel - runs smartGRC across SAP ECC, EWM, APO, HCM and more. Originally deployed in November 2014 for SoD monitoring and emergency access, upgraded to cloud/Fiori-based architecture in 2021. The story below describes the original 2014 implementation.
From the original 300-user Cyfrowy Polsat ECC deployment in 2014, the smartGRC footprint at Grupa Polsat Plus has grown to 3,500 SAP users across 14 systems - including Cyfrowy Polsat ECC, Polkomtel ECC, SAP EWM, APO and HCM. In 2021, the platform was upgraded to a cloud / Fiori-based architecture, replacing the original deployment with a modern, scalable foundation while preserving the operational continuity built up over 10+ years.
The story below describes the original 2014 implementation for Cyfrowy Polsat - the foundation that grew into the multi-entity Grupa Polsat Plus deployment.
Cyfrowy Polsat - one of the largest media and telecom groups in Poland with millions of customers - needed two things from SAP access governance. First, ongoing identification and analysis of Segregation of Duties (SoD) risks embedded in user and role authorizations defined in SAP. Second, a controlled, fully auditable way to manage emergency (firefighter) access accounts that hold broad SAP system access. The scope spanned finance, purchasing, sales, production planning and execution, material management and quality assurance.
smartSoD reporting provided identification and analysis of SoD risks and conflicts embedded in users and role authorizations defined in SAP. The data synchronization mechanism downloaded data from SAP to the local application server, with extended reporting capabilities allowing presentation in different dimensions (user or role) and different levels of detail.
smartAccess (firefighter workflow) managed emergency access accounts in a controlled, audit-ready way. Every action during emergency sessions was logged automatically - data changes, table modifications, program execution. For audit purposes, the application generated detailed control evidence documentation from each control execution performed by the responsible oversight person.
Business activities were mapped to corresponding authorization-level customization objects in SAP. The emergency access workflow is used by 15 people from technical and business supporting departments. SoD risks and conflicts monitoring is executed for all 300 users in SAP ECC.
"Security & Compliance application has been implemented by GRC Solutions and is in production use since November 2014 at Cyfrowy Polsat. Technical installation and implementation was made in 8 weeks and entire project with detailed process design was done in 12 weeks. Workflow for managing emergency access is being used by 15 people from technical and business supporting departments. Segregation of duties risks and conflicts monitoring is executed for 300 users in SAP ECC system."
See smartGRC running on a sandbox like yours - all modules, 19 AI agents, with your SAP context in mind.