← All case studies
Gobarto
FMCG · Meat processing
Signed reference · November 2022

SoD risk reduction
+ role redesign on SAP ERP

Gobarto S.A. - one of Poland's largest meat processing companies - deployed smartSoD and smartReport on SAP ERP for several hundred users in just 2 months. SoD risk identification, role rebuild for admins and consultants, and reduction of excessive permissions across the business.

2 mo
Implementation
2
SAP environments (DEV/TEST + PROD)
2
smartGRC modules
100%
On scope and on budget
Modules deployed:
smartSoD smartReport
The challenge

Excess permissions and SoD risks across the SAP estate

Gobarto runs SAP ERP across all major business processes with several hundred active users. Over time, role design had accumulated excessive permissions for admins and consultants, which translated into Segregation of Duties (SoD) risks and critical access exposure.

Gobarto's leadership needed three things: rebuild roles and access for administrators and consultants, raise the overall security posture of business operations by limiting excessive permissions, and reduce the count of SoD risks and critical access combinations - all on SAP ERP.

The solution

smartSoD + smartReport in 2 months, 2 environments

balance

SoD risk identification (smartSoD)

Automatic analysis and identification of risks tied to excessive SAP user permissions. Workshops with Gobarto's business representatives confirmed which risks apply to the company's specific business profile.

design_services

Risk-to-transaction mapping

Selected risks were technically mapped to SAP transactions and authorization objects in joint workshops with Gobarto's team. The mapped matrix was loaded into smartSoD.

content_cut

Excess permission detection

smartGRC's analysis surfaced exactly which permissions were excessive and required tightening in SAP ERP - giving Gobarto's IT and business a concrete list of changes to implement.

fact_check

Reporting layer (smartReport)

Standing reports for risk owners and auditors - SoD violations, excess access, role usage trends - made the cleanup auditable and repeatable.

engineering

Role rebuild & excess removal

Excessive admin and consultant permissions were replaced with dedicated, scope-appropriate IT roles. With excess access removed at the role level, future SoD drift stays controlled.

Project execution

Run by Gobarto's IT lead - on scope, on budget

The project was coordinated on the IT side by Artur Sołdek, IT Manager for Business Applications at Gobarto S.A., whose responsibilities included:

The project was delivered on time, in the agreed scope, and within budget.

format_quote
"The implementation took 2 months. The system was installed and configured across 2 environments: development-test and production. The implementation was delivered within the agreed scope and budget. The smartSoD and smartReport modules enable automatic analysis and identification of risks tied to excessive SAP user permissions. With the Gobarto team we ran business workshops and concept sessions, mapped the selected risks to transactions and authorization objects, loaded them into smartGRC - and the system surfaced exactly which permissions were excessive and required tightening in SAP ERP."
Artur Sołdek
IT Manager for Business Applications, Gobarto S.A.
Warsaw, 2 November 2022
Technical fact sheet

At a glance

SAP platformSAP ERP
SAP usersSeveral hundred (production users)
smartGRC modulessmartSoD, smartReport
EnvironmentsDevelopment-test + Production
Timeline2 months (2022)
IndustryFMCG · Meat processing

Need SoD risk reduction on your SAP ERP?

Book a 30-min call with our AI architect or see the live UX demo.