← All modules
smartAccess icon

smartAccess

Controlled emergency access to SAP - with audit trail and four-eyes approval.

smartAccess allows administrators and consultants in special situations (incident, business request, change) to gain access to broad SAP authorizations, while keeping the risk under control. Built-in controls let you pass any SAP audit while still letting maintenance work get done.

auto_awesome Our AI vision (in development)

AI agents in smartAccess

Three agents handle the routine work in firefighter access and escalate only what needs a human. Each agent has its own autonomy dial - your governance officer chooses how much the agent does and where humans stay in the loop.

shield_lock

Your governance officer owns the dial

Per agent, per environment, per risk level - tighten or loosen autonomy without redeploying code or filing engineering tickets. The agent never decides its own permission level. Business rules decide, and your team owns the rules.

Off
No AI
Suggest
AI advises
Approve
Human gate
Auto
Rules-governed
Agent 1 of 3 . Emergency Access

AI Pre-Approval for Emergency Access

Routine firefighter requests pre-approved in seconds based on user history, transaction scope and risk context. Your security team only reviews cases that genuinely need a human decision.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
smartAccess - Emergency access schedules
RESERVED
REQ-042815 . J. Nowak . FF_FI_01
FI corrections, month-end close . 20.04 06:00-10:00
auto_awesome AI PRE-APPROVED
RESERVED
REQ-042814 . M. Wisniewska . FF_MM_02
Order workflow failure . 20.04 05:30-09:30
auto_awesome AI PRE-APPROVED
PENDING
REQ-042802 . P. Kuriata . FF_BASIS_01
Failure after kernel update . scope wider than typical
escalator_warning HUMAN REVIEW
RESERVED
REQ-042816 . J. Nowak . FF_FI_02
Retro-corrections . 20.04 14:00-18:00
auto_awesome AI PRE-APPROVED

Illustrative mockup. AI PRE-APPROVED rows flow through autonomously when rules match. HUMAN REVIEW routes to your Security Officer.

What you see
  • looks_oneAI PRE-APPROVED badge on routine requests matching the rules.
  • looks_twoReasoning panel: history, scope match, ticket link, confidence score.
  • looks_3HUMAN REVIEW rows escalate to your Security Officer with annotations.
  • looks_4Every decision logged, reversible, audit-ready.
trending_up

From days to minutes

Median time-to-access for routine requests drops from hours/days to seconds. Your Security Officer workload concentrates on the cases that genuinely matter.

Agent 2 of 3 . Session Audit

AI Audit of Emergency Sessions

After every session closes, the agent analyses the transaction log, flags anomalies and generates the audit report. 100% of sessions reviewed, not just the 5-10% your team samples manually today.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
smartAccess . Session review
CLOSED
REQ-042799 . A. Kowalski . FF_SD_01
Emergency price list - key client . 19.04 15:00-16:30 . ECC_QAS
auto_awesome AI REVIEWED
auto_awesome
Agent verdict POSITIVE confidence 0.91

Session matches declared scope (SD price list maintenance). 12 transactions executed, all within ruleset SD-EMERGENCY. Linked ticket SNOW-12842 verified. No anomalies detected.

Transaction log (12)
check_circle VK11 . price condition 15:04
check_circle VK12 . change condition 15:08
check_circle V/06 . pricing procedure 15:22
more_horiz 9 more transactions, all within policy
Auditor: M. Wisniewska

Illustrative mockup. AI agent annotates closed FF sessions with verdict, confidence and reasoning. Auditor accepts or overrides.

What you see
  • looks_oneAI REVIEWED badge on every closed session, regardless of outcome.
  • looks_twoAgent verdict panel with confidence score and explainable reasoning.
  • looks_3Transactions tagged green / amber / red based on policy match and anomaly score.
  • looks_4Human auditor can Accept or Override - decision logged.
trending_up

From sample-based to 100% coverage

Today most companies audit 5-10% of FF sessions manually. The agent reviews every single session within minutes of closing.

Agent 3 of 3 . Justification Helper

AI Justification Helper

Agent drafts the business justification from the ticket, requester history and scope. Requesters accept, edit or regenerate - never staring at an empty textbox.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
smartAccess - New emergency access request
Requester
J. Nowak
FF role
FF_FI_01
Window
20.04 06:00-10:00
Ticket
SNOW-12842
auto_awesome AI DRAFT
Month-end close - FI corrections to clear stuck postings on document type SA in company code 1000. Required for period-end financial reporting. Linked to incident SNOW-12842 raised by Controlling at 04:50. Similar incidents handled in Mar 2026 and Feb 2026 by the same user. Scope limited to FB02, FB08, F-04.
history Drafted from 3 similar past incidents + ticket SNOW-12842

Illustrative mockup. AI drafts a complete justification from ticket and user history; the requester accepts, edits or regenerates.

What you see
  • looks_oneAI DRAFT badge under the justification field.
  • looks_twoNarrative pulled from ticket, similar past incidents and the requester profile.
  • looks_3Three actions: Accept and submit, Edit, Regenerate - human always in control.
  • looks_4Approval queue arrives with auditor-ready narratives, not empty fields.
trending_up

30 seconds, not 5 minutes

Requesters submit in seconds with consistent quality. Approval queue shrinks because narratives are clear enough to decide without follow-up.

Key features

check_circle

Time-bound firefighter sessions

Temporary broad access that automatically expires when the window closes. No manual cleanup.

check_circle

Four-eyes approval

Workflow requires sign-off from business manager and Security Officer before the session activates.

check_circle

Full activity log

Every transaction, every data change inside the session is captured - who, when, what, in which system.

check_circle

Reason & ticket number

Each session linked to a business justification (ServiceNow ticket, JIRA, incident) - audit-ready by default.

check_circle

Reviewer sign-off

After the session ends, a dedicated firefighter controller reviews the log and either approves or flags the incident.

check_circle

SOX, ITGC, GDPR ready

Controls designed for external audit requirements - easy sampling, PDF/Excel export.

Typical use cases

FAQ

Frequently asked questions about smartAccess

smartAccess vs SAP GRC Access Control - which is better for emergency access? expand_more

Both manage emergency (Firefighter) access, but smartAccess adds three capabilities SAP GRC AC lacks: (1) AI session log review that auto-flags risky transactions in Firefighter logs (we wrote a 6,500-word case study on 6 control signals AI surfaces that humans miss), (2) cross-domain JIT provisioning (SAP + non-SAP in one workflow), (3) transparent €15K-€30K/year pricing vs ~€250K/year for SAP GRC AC enterprise license.

Does smartAccess support Firefighter / emergency access workflows? expand_more

Yes. smartAccess is the platform behind our published case study "Firefighter AI vs Human: 6:0" - 6 months of production SAP S/4HANA Firefighter data, 600 sessions, 11 emergency accounts, 2.55M audit log entries. AI agents review session logs and surface risk patterns the classical session-by-session review misses. The Firefighter workflow includes request → approval → time-boxed grant → log review → certification.

Read the Firefighter AI case studyarrow_forward

Can smartAccess handle just-in-time (JIT) access provisioning? expand_more

Yes. smartAccess provisions standing access for routine work and JIT access for elevated operations (Firefighter, mass-data changes, payment runs). Time-boxed grants (4-hour / 8-hour / 24-hour) auto-revoke after the window. Approval workflows support single, dual (four-eyes) and tri-party approval depending on risk class.

How does smartAccess integrate with our existing IAM (SailPoint, Okta, Azure AD)? expand_more

smartAccess consumes identity data from any IAM via the universal XML adapter or direct connectors. The most common pattern: IAM owns identity lifecycle and provisioning of base roles; smartAccess owns elevated access requests, Firefighter grants, and SoD analytics. We have production customers running smartAccess with SailPoint, Okta, Azure AD and Oracle IDM.

Is smartAccess SOC 2 / ISO 27001 / SOX compliant? expand_more

smartGRC is built by GRC Solutions Sp. z o.o., with sister consulting practice GRC Advisory ISO 27001 certified, 15+ years SAP Security experience. smartAccess is designed to support SOX ITGC (especially payment authorization control), ISO 27001 A.9.4.4 (privileged utility programs) and the four-eyes principle. Audit trails are exportable in formats Big 4 auditors accept.

What's the implementation timeline for smartAccess? expand_more

Standard SAP Firefighter deployment: 4-6 weeks to first production session. Multi-system deployment (SAP + non-SAP elevated access): 8-10 weeks. Critical paths: role catalogue ingestion (week 1-2), approval workflow configuration (week 2-3), Firefighter policy and risk classes (week 3-4), pilot with 1-2 teams (week 4-5), full rollout (week 5-6).

Does smartAccess block toxic SoD risks during provisioning? expand_more

Yes. smartAccess integrates with smartSoD to perform pre-provisioning risk check: when a role grant would create a toxic SoD combination (e.g., "create vendor + approve payment"), the request is blocked or escalated for compensating-control review. The check runs at request time, not after the fact, so risks are prevented rather than detected.

Can we test smartAccess without a sales call? expand_more

Yes: the interactive demo is accessible without signup, no sales call required. Plus the 60-second ROI calculator shows the savings vs SAP GRC AC or Pathlock pricing on your own user count.

Related module

Works with smartSecurity

security
New module

smartAccess controls who gets in and for how long — smartSecurity watches what happens once they're inside. Firefighter and JIT grants from smartAccess feed straight into the Baseline Monitor: every elevation is checked against the security benchmark, and critical authorizations flagged for owner acknowledgement.

Explore smartSecurity arrow_forward
Combined coverage
  • check_circleFirefighter grant → auto-verified against security baseline
  • check_circleCritical auth register — every SAP_ALL / S_A.SYSTEM account tracked
  • check_circleEmergency access + vulnerability register = complete audit trail

Ready to see it live?

Try the interactive UX preview - no signup, no credit card.