InPost - leading European courier operator and parcel locker network - deployed all smartGRC modules for SAP S/4HANA in RISE (SAP Public Cloud) for 1000+ users in Q4 2025. Full SAP module coverage: FI, CO, MM, SD, PP, PM, PS, HCM.
InPost runs SAP S/4HANA in RISE (SAP Public Cloud) - Fiori-based, covering all core modules: FI, CO, MM, SD, PP, PM, PS and HCM. With 1000+ users, manual control of privileged access and SoD conflicts no longer scaled. Audit evidence was hard to produce on demand.
smartGRC was selected to automate privileged access, codify SoD risks into an enforceable matrix and provide auditors with a standing set of reports - all integrated with Microsoft Entra ID as the identity source.
New process for granting and revoking privileged access in a controlled, auditable way - delivered via smartAccess.
SoD risk and critical access repository, agreed with the business and implemented in smartSoD - reducing fraud exposure from excess permissions.
Improved security posture across business and IT processes in SAP, with full lineage from role assignment to executed transaction.
smartReport - a library of audit-ready reports for auditors and process owners: privileged access, SoD violations, access usage trends.
A complete picture of who works in SAP and what they can do - role catalog, access usage, anomaly signals - replacing tribal knowledge with auditable evidence.
smartGRC modules were installed on InPost's IT infrastructure (on-prem), with full configuration required for a functional production environment. A secure connection was established between smartGRC modules and SAP S/4HANA in RISE (Public Cloud), enabling data flow on roles, users and executed transactions - without impacting the SAP production environment managed by SAP.
The Segregation of Duties matrix was uploaded into smartSoD, providing the foundation for managing and monitoring SoD risk according to InPost's specific business guidelines. smartAccess was configured to enable monitored, controlled privileged access to SAP - with full audit trail for every session.
smartSoD, smartReport and smartAccess were configured to align with InPost's operational, compliance and reporting requirements. Process and technical documentation - user manuals, process descriptions, configuration notes and control procedures - was delivered alongside the platform.
Training was provided for business users and IT administrators - workshops, materials and a UAT report confirming the solution meets requirements and is ready for daily use.
Firefighter / Emergency Access - controlled privileged access with full audit trail
SoD risk matrix + analysis engine - real-time detection + mitigation controls
Audit-ready reports - privileged access, SoD violations, access usage trends
Periodic User Access Review (UAR) - workflows + manager attestation
Access request management - approval flows + provisioning
InPost's business model goes beyond standard settlements in the logistics industry. In addition to classic relationships with suppliers and couriers, a key stream of financial processes are settlements with land owners where each of the 61 000 Parcel Lockers across Europe is placed - that's hundreds of thousands of lease agreements and recurring payments to individual entities.
This specificity meant that a standard, "off-the-shelf" SoD matrix could not be the starting point. The Segregation of Duties risk matrix was built from scratch jointly - GRC experts provided the methodology and catalog of typical SAP risks, while the InPost team provided the business context of lease processes, partner agreement handling and payments to location owners. The result is a matrix that genuinely protects InPost against the risks stemming from their unique operating model.
Note: this view focuses on countries with active InPost / Mondial Relay group presence - specific per-country device numbers are subject to dynamic changes.
Deploying smartSoD in the production environment made it possible for the first time to see the full picture of risks. The findings surprised not only the business - also the IT team, which had historically built the SAP authorization landscape.
SoD risks are structural, not incidental - they stem from how roles are built, not from isolated bad assignments. Modifying existing roles does not eliminate the root causes - it only entrenches historical mistakes. The current role model does not scale as business processes evolve.
The smartSoD analysis leads to a clear recommendation: instead of modifying existing roles, we design a new model from the ground up - area by area, aligned with the least privilege principle.
Design a new role model from scratch, area by area - instead of modifying current, historically burdened structures.
Segregation of duties considered at the design phase of the role - not only at the control phase.
Consistent naming convention and unified rules for building roles across the entire organization.
Least-necessary-access principle - besides reducing risk, it directly cuts FUE licensing cost in S/4HANA.
Roll out new roles in parallel with phasing out current ones - minimizing impact on business continuity. Each pilot wave delivers lessons for the next.
A promise delivered by the project · click any block or card to see details
The pilot in the first business area is not an experiment - it is a refined protocol with clearly defined responsibilities of three teams: the Center of Excellence (COE), the GRC team and key business users.
| # | Task | Responsible | Phase |
|---|---|---|---|
| 1 | Define user scope in the selected area | Workshops: COE + Business | M1 |
| 2 | Select sample users (usage analysis + Wave #1) | Workshops: COE + Business | M1 |
| 3 | Analysis of actual transaction usage data | GRC team | M1-M2 |
| 4 | Consulting usage analysis + role catalog proposal | Key business users | M2 |
| 5 | Building and verifying the role catalog | Build: GRC · Verification: COE | M3 |
| 6 | Building and adjusting business roles | GRC team | M4 |
| 7 | Functional testing + UAT | COE + key users | M4 |
| 8 | Rolling out new roles + phasing out old ones (Wave #1, Wave #2) | GRC team | M5 |
Center of Excellence - SAP functional consultants, verify process correctness.
smartGRC consultants - analyze data, build roles, lead the deployment.
Business representatives - consult scope, approve role catalog, run UAT.
M1-M5 = first to fifth month of the pilot. Delivery of Wave #1 in subsequent areas incorporates lessons learned from the pilot and shortens to 3-4 months per area.
Click any system to see details
Today: SAP S/4HANA in RISE ↔ smartGRC on-prem ↔ Entra ID. In 2026: connecting the SaaS smartGRC layer with AI agents for real-time monitoring.
Authentication to smartGRC uses Microsoft Entra ID - users sign in with their InPost corporate accounts. No local passwords, MFA on the Entra ID side, full alignment with organizational security policy.
Employee data (name, department, manager, account activity) is automatically synced from Entra ID to smartGRC. Employee offboarding in HR = automatic SAP access deactivation by smartAccess - with no delay and no human error.
Today smartGRC modules run on InPost on-prem infrastructure. A migration project to smartgrc.eu Cloud - our enterprise-grade SaaS platform - is already underway:
InPost ran a structured evaluation of GRC solutions available on the market. Three alternatives were considered: SAP GRC Access Control, Pathlock and smartGRC. The choice landed on smartGRC for concrete substantive reasons.
Industry standard from SAP - Access Risk Analysis, Emergency Access Management, Business Role Management.
US enterprise player - SoD monitoring, access certification, multi-ERP support.
Polish product with 15+ years of SAP GRC expertise (GRC Advisory) - modules + consulting service + AI support.
smartGRC delivers a rich catalog of SoD risks as standard - risks that SAP GRC does not include. This was the biggest differentiator: not just a tool, but ready-made business content to deploy.
GRC Advisory consultants ran workshops with business representatives - able to explain what a specific risk actually is, what threat it carries and demonstrated the pattern of potential permission abuse. This allowed business to genuinely understand the value of the matrix.
smartGRC offered support for non-SAP systems, native integration with Microsoft Entra ID and the 2025 roadmap to launch AI agents - currently a live project workstream.
The solution delivered faster time-to-value than the competition. On top of that, InPost gained access to deep SAP authorization expertise, which - as later emerged during the project - proved to be critical for a successful deployment.
Compare SAP GRC maintenance costs (support ends 2027) with a smartGRC migration in a 3-year view. Interactive MD, license and add-on sliders - live calculations + PDF export. Open calculator →
| SAP platform | SAP S/4HANA in RISE (SAP Public Cloud), Fiori-based |
| SAP modules | FI, CO, MM, SD, PP, PM, PS, HCM |
| SAP users | 1000+ |
| smartGRC modules | smartAccess, smartSoD, smartReport, smartReview, smartWorkflow |
| Identity and SSO | Microsoft Entra ID (authentication + employee sync) |
| smartGRC hosting (today) | InPost IT infrastructure (on-prem) |
| smartGRC hosting (2026 roadmap) | smartgrc.eu Cloud (SaaS) - migration in progress |
| Deployment timeline | September - December 2025 (4 months) |
Book a 30-min call with our AI architect or see the interactive demo.