← All case studies
InPost
Courier services · Enterprise
Signed reference · September - December 2025

All smartGRC modules
on SAP S/4HANA in RISE

InPost - leading European courier operator and parcel locker network - deployed all smartGRC modules for SAP S/4HANA in RISE (SAP Public Cloud) for 1000+ users in Q4 2025. Full SAP module coverage: FI, CO, MM, SD, PP, PM, PS, HCM.

1000+
SAP users
5
smartGRC modules
8
SAP modules covered
4 msc
September - December 2025
The challenge

Access control on S/4HANA in the cloud required automation and audit trail

InPost runs SAP S/4HANA in RISE (SAP Public Cloud) - Fiori-based, covering all core modules: FI, CO, MM, SD, PP, PM, PS and HCM. With 1000+ users, manual control of privileged access and SoD conflicts no longer scaled. Audit evidence was hard to produce on demand.

smartGRC was selected to automate privileged access, codify SoD risks into an enforceable matrix and provide auditors with a standing set of reports - all integrated with Microsoft Entra ID as the identity source.

Project goals

5 goals, one platform

verified_user

1. Privileged access automation

New process for granting and revoking privileged access in a controlled, auditable way - delivered via smartAccess.

balance

2. SoD and critical access matrix

SoD risk and critical access repository, agreed with the business and implemented in smartSoD - reducing fraud exposure from excess permissions.

security

3. Business and IT process security

Improved security posture across business and IT processes in SAP, with full lineage from role assignment to executed transaction.

fact_check

4. Audit and reporting made simple

smartReport - a library of audit-ready reports for auditors and process owners: privileged access, SoD violations, access usage trends.

visibility

5. Transparency: who can do what in SAP

A complete picture of who works in SAP and what they can do - role catalog, access usage, anomaly signals - replacing tribal knowledge with auditable evidence.

Scope and deliverables

smartGRC integrated with S/4HANA RISE and Microsoft Entra ID

smartGRC modules were installed on InPost's IT infrastructure (on-prem), with full configuration required for a functional production environment. A secure connection was established between smartGRC modules and SAP S/4HANA in RISE (Public Cloud), enabling data flow on roles, users and executed transactions - without impacting the SAP production environment managed by SAP.

The Segregation of Duties matrix was uploaded into smartSoD, providing the foundation for managing and monitoring SoD risk according to InPost's specific business guidelines. smartAccess was configured to enable monitored, controlled privileged access to SAP - with full audit trail for every session.

smartSoD, smartReport and smartAccess were configured to align with InPost's operational, compliance and reporting requirements. Process and technical documentation - user manuals, process descriptions, configuration notes and control procedures - was delivered alongside the platform.

Training was provided for business users and IT administrators - workshops, materials and a UAT report confirming the solution meets requirements and is ready for daily use.

Platform scope

5 smartGRC modules deployed at InPost

Business specifics

Why the SoD matrix had to be designed specifically for InPost

61 000
Parcel Locker devices across Europe
27 000+
devices in Poland alone - the largest network in Europe
3
settlement streams: suppliers, couriers, land owners

InPost's business model goes beyond standard settlements in the logistics industry. In addition to classic relationships with suppliers and couriers, a key stream of financial processes are settlements with land owners where each of the 61 000 Parcel Lockers across Europe is placed - that's hundreds of thousands of lease agreements and recurring payments to individual entities.

This specificity meant that a standard, "off-the-shelf" SoD matrix could not be the starting point. The Segregation of Duties risk matrix was built from scratch jointly - GRC experts provided the methodology and catalog of typical SAP risks, while the InPost team provided the business context of lease processes, partner agreement handling and payments to location owners. The result is a matrix that genuinely protects InPost against the risks stemming from their unique operating model.

Operational reach · dashboard

InPost Parcel Lockers in Europe

Europe total
61 000
Parcel Locker devices
Largest network in Europe
Poland
27 000+
44% of all Parcel Locker devices in Europe - InPost is the Polish pioneer and leader of the out-of-home delivery model.
United Kingdom
UK
InPost UK - rapid expansion
France
FR
Mondial Relay network - 2021 acquisition
Italy
IT
Growing in-store network
Spain
ES
Expansion with logistics partners
Portugal
PT
Iberia coverage
BeNeLux
NL BE LU
Cross-border e-commerce hub
Germany
DE
Strategic DACH market
Total
10+ countries
European reach of InPost / Mondial Relay

Note: this view focuses on countries with active InPost / Mondial Relay group presence - specific per-country device numbers are subject to dynamic changes.

Scale of the challenge

What the first SoD analysis revealed

Deploying smartSoD in the production environment made it possible for the first time to see the full picture of risks. The findings surprised not only the business - also the IT team, which had historically built the SAP authorization landscape.

1100+
active users included in the analysis
majority
of users had at least one SoD risk
Top 10
risk types cover 60% of all violations - clear priorities
128 roles
with broad privileges - candidates for immediate reduction

lightbulbKey finding

SoD risks are structural, not incidental - they stem from how roles are built, not from isolated bad assignments. Modifying existing roles does not eliminate the root causes - it only entrenches historical mistakes. The current role model does not scale as business processes evolve.

Methodical approach

Rebuild roles from scratch instead of patching

The smartSoD analysis leads to a clear recommendation: instead of modifying existing roles, we design a new model from the ground up - area by area, aligned with the least privilege principle.

1. Build, don't patch

Design a new role model from scratch, area by area - instead of modifying current, historically burdened structures.

2. SoD by design, not by control

Segregation of duties considered at the design phase of the role - not only at the control phase.

3. Standardize the role model

Consistent naming convention and unified rules for building roles across the entire organization.

4. Least privilege + FUE minimization

Least-necessary-access principle - besides reducing risk, it directly cuts FUE licensing cost in S/4HANA.

5. Gradual migration without operational risk

Roll out new roles in parallel with phasing out current ones - minimizing impact on business continuity. Each pilot wave delivers lessons for the next.

timelineRoadmap

A promise delivered by the project · click any block or card to see details

2025 2026 2027 2025 Deployment + matrix Q1-Q2 2026 Role catalog + pilot JUN-SEP 2026 SaaS + AI Agents AI Q3-Q4 2026 Wave #1: building 2027 Wave #2 + smartReview
2025
Tool deployment + matrix
Installation of smartGRC modules, preparation of a dedicated SoD matrix in workshops with the InPost business
Q1-Q2 2026
Role catalog + pilot
Build a new catalog, pilot deployment in the first business area
auto_awesome AI
June-September 2026
SaaS smartGRC + AI agents
Connecting the SaaS smartGRC version with AI agents for continuous SoD risk monitoring and FF (Firefighter) session analysis
Q3-Q4 2026
Wave #1: building + UAT
Sprint building, functional tests, UAT, production rollout for the first area
2027
Wave #2: additional areas
Extending the model to remaining areas + launching periodic access reviews (smartReview)
Pilot methodology

How the pilot looks in practice - 8 steps, 5 months

The pilot in the first business area is not an experiment - it is a refined protocol with clearly defined responsibilities of three teams: the Center of Excellence (COE), the GRC team and key business users.

# Task Responsible Phase
1 Define user scope in the selected area Workshops: COE + Business M1
2 Select sample users (usage analysis + Wave #1) Workshops: COE + Business M1
3 Analysis of actual transaction usage data GRC team M1-M2
4 Consulting usage analysis + role catalog proposal Key business users M2
5 Building and verifying the role catalog Build: GRC · Verification: COE M3
6 Building and adjusting business roles GRC team M4
7 Functional testing + UAT COE + key users M4
8 Rolling out new roles + phasing out old ones (Wave #1, Wave #2) GRC team M5
groupsCOE

Center of Excellence - SAP functional consultants, verify process correctness.

engineeringGRC team

smartGRC consultants - analyze data, build roles, lead the deployment.

badgeKey users

Business representatives - consult scope, approve role catalog, run UAT.

M1-M5 = first to fifth month of the pilot. Delivery of Wave #1 in subsequent areas incorporates lessons learned from the pilot and shortens to 3-4 months per area.

Identity architecture and 2026 roadmap

Microsoft Entra ID as the source of truth about employees

System architecture · today → 2026 roadmap

Click any system to see details

Today (2025) SAP PUBLIC CLOUD SAP S/4HANA in RISE 1000+ users · Fiori FI · CO · MM · SD · PP · PM · PS · HCM ON-PREM · INPOST DC smartGRC 5 modules smartAccess · smartSoD smartReport · smartReview · smartWorkflow MICROSOFT CLOUD Entra ID Identity Provider SSO · MFA Employee sync (auto) SAP data SSO + sync Migration 2026 Roadmap 2026 · SaaS + AI smartgrc.eu CLOUD (SaaS) smartGRC + AI Agents SoD Monitoring · Session Audit · Anomaly Detection · GRC Copilot AI

Today: SAP S/4HANA in RISE ↔ smartGRC on-prem ↔ Entra ID. In 2026: connecting the SaaS smartGRC layer with AI agents for real-time monitoring.

passkey

SSO via Entra ID (formerly Azure AD)

Authentication to smartGRC uses Microsoft Entra ID - users sign in with their InPost corporate accounts. No local passwords, MFA on the Entra ID side, full alignment with organizational security policy.

sync

Employee sync with Entra ID

Employee data (name, department, manager, account activity) is automatically synced from Entra ID to smartGRC. Employee offboarding in HR = automatic SAP access deactivation by smartAccess - with no delay and no human error.

rocket_launch
Roadmap 2026 · project in progress

smartGRC on-prem → smartgrc.eu Cloud migration

Today smartGRC modules run on InPost on-prem infrastructure. A migration project to smartgrc.eu Cloud - our enterprise-grade SaaS platform - is already underway:

  • Long-term: less infrastructure to maintain on InPost side - operational costs move to an OPEX model
  • Updates and patches managed by GRC Solutions - InPost gets new functionality without implementation projects
  • Same integration with S/4HANA RISE and Entra ID - only the smartGRC hosting layer changes
  • Non-invasive migration for end users - same URLs, same UI, same SSO
Selection process

Why smartGRC - three solutions considered

InPost ran a structured evaluation of GRC solutions available on the market. Three alternatives were considered: SAP GRC Access Control, Pathlock and smartGRC. The choice landed on smartGRC for concrete substantive reasons.

Considered
business

SAP GRC Access Control

Industry standard from SAP - Access Risk Analysis, Emergency Access Management, Business Role Management.

Limitations for InPost
  • Sparse "out-of-the-box" SoD matrix
  • No SoD business workshops in standard scope
  • Locked into the SAP ecosystem
  • Longer time-to-value
Considered
shield

Pathlock

US enterprise player - SoD monitoring, access certification, multi-ERP support.

Limitations for InPost
  • No local SoD-with-business expertise
  • Standard matrix without CEE context
  • Licensing oriented toward large US enterprise
  • Longer implementation process
check_circleChosen
verified

smartGRC

Polish product with 15+ years of SAP GRC expertise (GRC Advisory) - modules + consulting service + AI support.

Key advantages for InPost
  • Rich SoD matrix with concrete risks
  • SoD-with-business workshops led by GRC Advisory
  • Non-SAP support + Entra ID + AI agents
  • Shorter time-to-value
  • Authorization expertise - critical in the project

insightsKey factors behind choosing smartGRC

1

Substantive SoD matrix with ready-made risks

smartGRC delivers a rich catalog of SoD risks as standard - risks that SAP GRC does not include. This was the biggest differentiator: not just a tool, but ready-made business content to deploy.

2

SoD workshops with the business

GRC Advisory consultants ran workshops with business representatives - able to explain what a specific risk actually is, what threat it carries and demonstrated the pattern of potential permission abuse. This allowed business to genuinely understand the value of the matrix.

3

Extensibility beyond SAP

smartGRC offered support for non-SAP systems, native integration with Microsoft Entra ID and the 2025 roadmap to launch AI agents - currently a live project workstream.

4

Shorter deployment time + authorization expertise

The solution delivered faster time-to-value than the competition. On top of that, InPost gained access to deep SAP authorization expertise, which - as later emerged during the project - proved to be critical for a successful deployment.

calculate
Calculate your case
3-year TCO calculator: SAP GRC vs smartGRC

Compare SAP GRC maintenance costs (support ends 2027) with a smartGRC migration in a 3-year view. Interactive MD, license and add-on sliders - live calculations + PDF export. Open calculator →

Technical fact sheet

Key facts

SAP platformSAP S/4HANA in RISE (SAP Public Cloud), Fiori-based
SAP modulesFI, CO, MM, SD, PP, PM, PS, HCM
SAP users1000+
smartGRC modulessmartAccess, smartSoD, smartReport, smartReview, smartWorkflow
Identity and SSOMicrosoft Entra ID (authentication + employee sync)
smartGRC hosting (today)InPost IT infrastructure (on-prem)
smartGRC hosting (2026 roadmap)smartgrc.eu Cloud (SaaS) - migration in progress
Deployment timelineSeptember - December 2025 (4 months)

Want a similar deployment for your SAP estate?

Book a 30-min call with our AI architect or see the interactive demo.