The Polish arm of Volkswagen Group rebuilt SAP authorizations from the ground up - new SoD matrix, complete role redesign based on MENU/ORG model, and full security governance using smartGRC.
Volkswagen Group Poland - then operating as KPI Poland Company - needed to rebuild SAP authorization architecture from the ground up. The legacy role structure had grown organically over years across Finance, Controlling, Logistics, Purchasing, Sales and IT processes. The team needed a clean SoD matrix, a structured business role catalog, and modern role architecture aligned to MENU/ORG conception with full audit-grade governance.
The 11-month engagement covered business processes analysis in Finance, Controlling, Logistics, Purchasing, Sales and IT areas. Out of this came risk identification and a full Segregation of Duties Matrix capturing every conflict relevant to the VW landscape.
smartArchitect hosted the new business roles catalog developed during the project. The team built the new role architecture in the SAP system based on a clean MENU/ORG roles conception - eliminating accumulated technical debt.
smartSoD reporting covered identification and analysis of SoD conflicts embedded in users and role authorizations. The application integrates with SAP via dedicated interface for synchronizing user permission data.
The project completed with business UAT and roles assigned to users in production. Environment was installed by GRC Solutions employees on hardware provided by the customer, with further configuration carried out jointly.
"GRC Solutions Company project team has demonstrated a high level of professionalism. Cooperation with the GRC Solutions Company has been effective and successful. The work has been carried out in accordance with the terms contained in the contract. Products of the work produced by a team of GRC Solutions Company were in line with the expectations of the Company and were characterized by very high quality. The application supports performing privileges and segregation of duties reviews for SAP users, and effectively supports addressing the risks associated with segregation of duties conflicts arising from extended user privileges defined in SAP system."
See smartGRC running on a sandbox like yours - all modules, 19 AI agents, with your SAP context in mind.