Reporting SoD risks and critical access across heterogeneous IT environments.
smartReport enables reporting across various IT systems (SAP ERP, SAP S/4 HANA, HCM, Active Directory, Teradata, MSSF15, SPECTRUM) of access in the context of risks to safe business process execution. The application enables fast and cost-effective identification and elimination of excessive permissions.
3 agents handle the routine work in this module and escalate only what needs a human. Each agent has its own autonomy dial - your governance officer chooses how much the agent does and where humans stay in the loop.
Per agent, per environment, per risk level - tighten or loosen autonomy without redeploying code or filing engineering tickets. The agent never decides its own permission level. Business rules decide, and your team owns the rules.
Agent compares role contents against actual TX usage over 12 months and proposes safe pruning candidates. Attack surface reduction without breaking active workflows.
Pruning removes 45% of the role's TX surface. Risk score drops from 78 to 41. No active user loses any TX they have used in the last 12 months.
Illustrative mockup from the smartReport role analyzer. Pruning plan lists TX codes with usage stats; user adopts the full plan or trims by hand.
Fewer TX codes per role means fewer paths if a credential is compromised. Audit findings on excessive access drop significantly.
Agent predicts likely audit findings based on patterns from prior audits and the current state of access. Walks into the audit knowing what's coming.
Resolving the top 3 issues drops predicted findings from 7 to 2. Time-to-fix estimate: 12 working days.
Illustrative mockup from the smartReport audit forecast. Each predicted finding has a probability and an action that lowers it before audit.
Problems fixed weeks before an audit are housekeeping. The same issues found by external auditors become formal findings requiring management response.
Agent baselines each user's normal pattern and flags deviations: off-hours, permission spikes, geographic outliers, unusual TX combinations.
Illustrative mockup from the smartReport anomaly feed. Each entry shows a confidence score and the baseline it deviates from.
Off-hours work and sudden permission expansion become visible the day they happen instead of during the next compliance review.
Zero usage by any of 142 users in last 12 months. Safe to prune. Estimated risk reduction: ~25% of attack surface.
Illustrative mockup. The Excess Access Pruning Agent compares role contents to actual transaction usage and recommends safe removals.
Role catalog shrinks over time. Audit surface area drops. Compliance reviews get faster.
SAP ERP, S/4 HANA, HCM, Active Directory, Teradata, MSSF15, SPECTRUM - one reporting layer across silos.
Full picture: who has what, where are the SoD risks, where the excess. Starting point for optimization.
Reports show permissions users hold but do not actually need for their role.
Cross-system SoD - e.g. vendor creation in SAP + payment approval in a different system.
PDF/Excel report with clear structure - ready attachment for audit documentation.
After fixes are applied - a re-run report shows progress. You measure whether actions worked.
smartReport ships with 10+ compliance reports calibrated for SOX, ISO 27001, GDPR, and SAP audit best practices. Key reports: User access matrix, SoD risk overview, Firefighter session summary, Privileged access review, Role-to-user assignment audit, Change document review, Authorization drift analysis, Access concentration risk. All reports are export-ready in CSV/Excel/PDF for external auditor working papers.
Yes. Custom report definition uses a SQL-like query builder against the normalized smartGRC data model (users, roles, permissions, sessions, audit events). Reports can combine data from multiple SAP systems and non-SAP systems (via XML adapter). Custom reports are scheduled, distributed via email, and audit-trail tracked.
smartReport normalizes data from multiple SAP systems (ECC, S/4HANA, multiple clients) into a single data model. Reports can scope to a single system, a system cluster (e.g., all production), or cross-system (e.g., users with the same role across 5 systems). Multi-system deployment is included in Professional and Enterprise plans.
smartReport is designed to support SOX ITGC reporting requirements (especially access certification and segregation of duties evidence) and GDPR-required data processing records. All report generation is audit-trail tracked (who ran the report, when, with what parameters). smartGRC is GDPR-compliant by design, hosted in EU data centers.
Partially. SAP Solution Manager covers a broader scope including system monitoring and change management. smartReport replaces the access management and audit reporting components of Solution Manager with a modern UX and better cross-system data model. Most customers use smartReport alongside Solution Manager rather than replacing it.
smartReport is included in the Starter plan (€15K/year, up to 400 SAP users) with 10+ compliance reports. Professional (€30K/year, 800 users) and Enterprise (custom pricing, full governance) include custom report builder and multi-system support. See pricing tiers.
Yes. smartReport exposes all report data via REST API and scheduled CSV/Excel exports. Customers integrate with Power BI, Tableau, Qlik and similar tools for dashboarding. The REST API is documented and supports OAuth 2.0 authentication.
Yes: the interactive demo includes the smartReport interface with sample data. The Free plan covers 3 basic reports (SoD, users, roles) for up to 25 SAP users.
smartSecurity generates the security findings — smartReport turns them into audit-ready evidence packs. The Compliance Advisor agent in smartSecurity maps each finding to NIS2, ISO 27001, GDPR and DORA controls, and pipes it straight into pre-built report templates here.
Explore smartSecurity arrow_forwardTry the interactive UX preview - no signup, no credit card.