← All modules
smartReport icon

smartReport

Reporting SoD risks and critical access across heterogeneous IT environments.

smartReport enables reporting across various IT systems (SAP ERP, SAP S/4 HANA, HCM, Active Directory, Teradata, MSSF15, SPECTRUM) of access in the context of risks to safe business process execution. The application enables fast and cost-effective identification and elimination of excessive permissions.

auto_awesome Our AI vision (in development)

AI agents in smartReport

3 agents handle the routine work in this module and escalate only what needs a human. Each agent has its own autonomy dial - your governance officer chooses how much the agent does and where humans stay in the loop.

shield_lock

Your governance officer owns the dial

Per agent, per environment, per risk level - tighten or loosen autonomy without redeploying code or filing engineering tickets. The agent never decides its own permission level. Business rules decide, and your team owns the rules.

Off
No AI
Suggest
AI advises
Approve
Human gate
Auto
Rules-governed
Agent 1 of 3 . Excess Access Pruning

AI Excess Access Pruning

Agent compares role contents against actual TX usage over 12 months and proposes safe pruning candidates. Attack surface reduction without breaking active workflows.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
Role SAP_FI_SUPER - usage analysis
smartReport
SAP_FI_SUPER . 47 assigned users . 312 TX codes
OVERSIZED
94
Active TX
76
Low usage
142
Unused 12m
content_cut AI-recommended pruning (142 TX)
- SE38 . program execution . 0 uses in 365d
- SM30 . table maintenance . 0 uses
- SU01 . user admin . 0 uses
- RZ10 . profile maintenance . 0 uses
- STMS . transport mgmt . 0 uses
... 137 more
Estimated outcome

Pruning removes 45% of the role's TX surface. Risk score drops from 78 to 41. No active user loses any TX they have used in the last 12 months.

Illustrative mockup from the smartReport role analyzer. Pruning plan lists TX codes with usage stats; user adopts the full plan or trims by hand.

What you see
  • looks_oneRole profile with Active / Low usage / Unused breakdown.
  • looks_twoAI-recommended pruning list with usage evidence per TX.
  • looks_3Estimated outcome: TX surface reduction, risk score drop.
  • looks_4Guarantee: no active user loses a TX they actually use.
trending_up

Right-size every role, smaller attack surface

Fewer TX codes per role means fewer paths if a credential is compromised. Audit findings on excessive access drop significantly.

Agent 2 of 3 . Compliance Prediction

AI Compliance Prediction

Agent predicts likely audit findings based on patterns from prior audits and the current state of access. Walks into the audit knowing what's coming.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
Audit forecast - SOX 404 readiness
smartReport
Q2 2026 audit . 47 days out
3 historical audits in model
7
Predicted findings
Based on patterns from 2024 and 2025 audits + current state
89%
SoD - 12 unresolved Post and Approve conflicts
Same pattern triggered 2 findings in 2024. Likely audit citation.
71%
214 unused roles > 90 days
Auditors flagged 180+ unused last year. Likely repeat.
63%
FF reviews missing for 8 sessions
Documented review evidence missing - prior finding type.
If you act now

Resolving the top 3 issues drops predicted findings from 7 to 2. Time-to-fix estimate: 12 working days.

Illustrative mockup from the smartReport audit forecast. Each predicted finding has a probability and an action that lowers it before audit.

What you see
  • looks_onePredicted-findings count + days-to-audit.
  • looks_twoEach finding shows probability and historical basis.
  • looks_3Linked remediation actions with effort estimate.
  • looks_4If you act now panel: forecast after fixing the top 3.
trending_up

Issues caught early are routine work

Problems fixed weeks before an audit are housekeeping. The same issues found by external auditors become formal findings requiring management response.

Agent 3 of 3 . Anomaly Detection

AI Anomaly Detection

Agent baselines each user's normal pattern and flags deviations: off-hours, permission spikes, geographic outliers, unusual TX combinations.

tune AI autonomy level
Off
Suggest
Approve
Autonomous
Anomaly feed - last 24h
smartReport
schedule
3
Off-hours
trending_up
2
Permission spike
public
1
Geo anomaly
priority_high
Permission spike . T. Kowalski
Granted 8 new high-risk TX codes in 2h. User profile baseline: 0 changes / month.
15 May 03:14 . confidence 0.92
schedule
Off-hours activity . J. Nowak
Logged in at 23:47 (typical: 08:00-17:00). Ran F-02, F-04, FB02 from new IP.
14 May 23:47 . confidence 0.78
public
Geo anomaly . M. Wisniewska
Login from CZ, previous 90d: only PL. Routine TX run, but worth confirming with user.
15 May 10:08 . confidence 0.65
visibility
Unusual TX combination . A. Lewicki
Ran SU01 then SE38 within 4 minutes. Pattern not seen in 365d history.
15 May 11:22 . confidence 0.71

Illustrative mockup from the smartReport anomaly feed. Each entry shows a confidence score and the baseline it deviates from.

What you see
  • looks_oneDaily counts across anomaly types in a compact strip.
  • looks_twoEach anomaly has confidence score and baseline reference.
  • looks_3One-click context: what was expected vs what happened.
  • looks_4Routed to SOC / security team or to the affected user's manager.
trending_up

Insider-threat signals surfaced early

Off-hours work and sudden permission expansion become visible the day they happen instead of during the next compliance review.

Key features

smartReport · Excess access analysis
work
Z_FI_POSTING_FULL
48 transactions assigned · 142 users · last 90 days
auto_awesome PRUNING CANDIDATE
auto_awesome
Agent recommends removing 12 of 48 transactions

Zero usage by any of 142 users in last 12 months. Safe to prune. Estimated risk reduction: ~25% of attack surface.

Transaction usage (top of list)
FB60
128 use KEEP
FB01
96 use KEEP
SE38
0 use PRUNE
SU01
0 use PRUNE
more_horiz 10 more PRUNE candidates + 34 KEEP

Illustrative mockup. The Excess Access Pruning Agent compares role contents to actual transaction usage and recommends safe removals.

What you see
  • looks_oneRole tagged PRUNING CANDIDATE when agent finds clear safe-removal candidates.
  • looks_twoEach TX evaluated by usage: KEEP vs PRUNE.
  • looks_3Role owner can accept the whole plan or review TX by TX.
trending_up

Least-privilege at scale

Role catalog shrinks over time. Audit surface area drops. Compliance reviews get faster.

check_circle

Multi-system support

SAP ERP, S/4 HANA, HCM, Active Directory, Teradata, MSSF15, SPECTRUM - one reporting layer across silos.

check_circle

Authorization state diagnosis

Full picture: who has what, where are the SoD risks, where the excess. Starting point for optimization.

check_circle

Excess permission detection

Reports show permissions users hold but do not actually need for their role.

check_circle

Cross-system SoD risks

Cross-system SoD - e.g. vendor creation in SAP + payment approval in a different system.

check_circle

Auditor-ready exports

PDF/Excel report with clear structure - ready attachment for audit documentation.

check_circle

Repeatable verification

After fixes are applied - a re-run report shows progress. You measure whether actions worked.

When does it make sense?

FAQ

Frequently asked questions about smartReport

What reports does smartReport include out of the box? expand_more

smartReport ships with 10+ compliance reports calibrated for SOX, ISO 27001, GDPR, and SAP audit best practices. Key reports: User access matrix, SoD risk overview, Firefighter session summary, Privileged access review, Role-to-user assignment audit, Change document review, Authorization drift analysis, Access concentration risk. All reports are export-ready in CSV/Excel/PDF for external auditor working papers.

Can I create custom reports in smartReport? expand_more

Yes. Custom report definition uses a SQL-like query builder against the normalized smartGRC data model (users, roles, permissions, sessions, audit events). Reports can combine data from multiple SAP systems and non-SAP systems (via XML adapter). Custom reports are scheduled, distributed via email, and audit-trail tracked.

How does smartReport handle data from multiple SAP systems? expand_more

smartReport normalizes data from multiple SAP systems (ECC, S/4HANA, multiple clients) into a single data model. Reports can scope to a single system, a system cluster (e.g., all production), or cross-system (e.g., users with the same role across 5 systems). Multi-system deployment is included in Professional and Enterprise plans.

Is smartReport SOX and GDPR compliant? expand_more

smartReport is designed to support SOX ITGC reporting requirements (especially access certification and segregation of duties evidence) and GDPR-required data processing records. All report generation is audit-trail tracked (who ran the report, when, with what parameters). smartGRC is GDPR-compliant by design, hosted in EU data centers.

Can smartReport replace SAP Solution Manager reporting? expand_more

Partially. SAP Solution Manager covers a broader scope including system monitoring and change management. smartReport replaces the access management and audit reporting components of Solution Manager with a modern UX and better cross-system data model. Most customers use smartReport alongside Solution Manager rather than replacing it.

How is smartReport licensed? expand_more

smartReport is included in the Starter plan (€15K/year, up to 400 SAP users) with 10+ compliance reports. Professional (€30K/year, 800 users) and Enterprise (custom pricing, full governance) include custom report builder and multi-system support. See pricing tiers.

Does smartReport integrate with our BI/analytics platform (Power BI, Tableau)? expand_more

Yes. smartReport exposes all report data via REST API and scheduled CSV/Excel exports. Customers integrate with Power BI, Tableau, Qlik and similar tools for dashboarding. The REST API is documented and supports OAuth 2.0 authentication.

Can I test smartReport without commitment? expand_more

Yes: the interactive demo includes the smartReport interface with sample data. The Free plan covers 3 basic reports (SoD, users, roles) for up to 25 SAP users.

Related module

Works with smartSecurity

security
New module

smartSecurity generates the security findings — smartReport turns them into audit-ready evidence packs. The Compliance Advisor agent in smartSecurity maps each finding to NIS2, ISO 27001, GDPR and DORA controls, and pipes it straight into pre-built report templates here.

Explore smartSecurity arrow_forward
Combined coverage
  • check_circleContinuous baseline monitoring → auto-mapped audit evidence
  • check_circleVulnerability register → CVSS-prioritized executive summary
  • check_circleNIS2, ISO 27001, GDPR, DORA — one export, four frameworks

Ready to see it live?

Try the interactive UX preview - no signup, no credit card.