Gobarto S.A. - one of Poland's largest meat processing companies - deployed smartSoD and smartReport on SAP ERP for several hundred users in just 2 months. SoD risk identification, role rebuild for admins and consultants, and reduction of excessive permissions across the business.
Gobarto runs SAP ERP across all major business processes with several hundred active users. Over time, role design had accumulated excessive permissions for admins and consultants, which translated into Segregation of Duties (SoD) risks and critical access exposure.
Gobarto's leadership needed three things: rebuild roles and access for administrators and consultants, raise the overall security posture of business operations by limiting excessive permissions, and reduce the count of SoD risks and critical access combinations - all on SAP ERP.
Automatic analysis and identification of risks tied to excessive SAP user permissions. Workshops with Gobarto's business representatives confirmed which risks apply to the company's specific business profile.
Selected risks were technically mapped to SAP transactions and authorization objects in joint workshops with Gobarto's team. The mapped matrix was loaded into smartSoD.
smartGRC's analysis surfaced exactly which permissions were excessive and required tightening in SAP ERP - giving Gobarto's IT and business a concrete list of changes to implement.
Standing reports for risk owners and auditors - SoD violations, excess access, role usage trends - made the cleanup auditable and repeatable.
Excessive admin and consultant permissions were replaced with dedicated, scope-appropriate IT roles. With excess access removed at the role level, future SoD drift stays controlled.
The project was coordinated on the IT side by Artur Sołdek, IT Manager for Business Applications at Gobarto S.A., whose responsibilities included:
The project was delivered on time, in the agreed scope, and within budget.
"The implementation took 2 months. The system was installed and configured across 2 environments: development-test and production. The implementation was delivered within the agreed scope and budget. The smartSoD and smartReport modules enable automatic analysis and identification of risks tied to excessive SAP user permissions. With the Gobarto team we ran business workshops and concept sessions, mapped the selected risks to transactions and authorization objects, loaded them into smartGRC - and the system surfaced exactly which permissions were excessive and required tightening in SAP ERP."
| SAP platform | SAP ERP |
| SAP users | Several hundred (production users) |
| smartGRC modules | smartSoD, smartReport |
| Environments | Development-test + Production |
| Timeline | 2 months (2022) |
| Industry | FMCG · Meat processing |
Book a 30-min call with our AI architect or see the live UX demo.