Full flexibility in approval flows - with preventive SoD check before access is granted.
smartWorkflow provides full flexibility in configuring workflows for permission management processes. The built-in SoD risk database enables proactive "what-if" analysis during authorization request approval. The system automatically assigns authorizations and uses an intuitive workflow to track the process, sending email notifications to all participants.
2 agents handle the routine work in this module and escalate only what needs a human. Each agent has its own autonomy dial - your governance officer chooses how much the agent does and where humans stay in the loop.
Per agent, per environment, per risk level - tighten or loosen autonomy without redeploying code or filing engineering tickets. The agent never decides its own permission level. Business rules decide, and your team owns the rules.
Agent recommends a complete role package for a new hire based on successful peer profiles in the same role and department. Day-1 productivity instead of two weeks of permission tickets.
Illustrative mockup from the smartWorkflow new-hire flow. Each suggested role shows match rate with peer profiles; users can accept or trim.
New hires start with a working role package on day one. Two weeks of 'I'm missing permission for X' tickets disappear.
Agent pre-approves routine access requests, leaving humans to focus on exceptions and high-risk cases. Manager workload drops; SLA improves.
Illustrative mockup from the smartWorkflow request queue. PRE-APPROVED rows flow through automatically; ESCALATE rows route to a human reviewer.
Median time-to-access for routine requests drops from days to seconds. Manager workload concentrates on the 30% that genuinely needs thought.
Analyzed 11 FI Specialists in Warszawa department with same job code. Recommended package below; confidence 0.88.
Illustrative mockup. The Onboarding Assistant Agent recommends a complete role package based on peers with the same job code in the same team.
No more back-and-forth tickets. New hire gets the right access on day one based on what their team actually needs.
Any structure: Manager → Security → Process Owner → Audit. Per request type, per system, per risk.
Before approval: the system shows whether granting this role will create a new SoD conflict. Conscious decision.
After approval - permissions go to SAP / target system without manual admin clicking.
Every participant gets a notification with an action link. Escalation when no response in X days.
Who requested, who approved, what SoD risks were present, what controls were applied. Audit material.
Employee submits requests through an intuitive portal - no helpdesk emails.
smartWorkflow automates the request → approval → provisioning → review lifecycle for SAP access. Key workflows out of the box: Access request (role assignment), Firefighter request (emergency access), Role modification (change a role definition), Periodic review campaign (recertification), De-provisioning (leaver workflow). All workflows include four-eyes approval, audit trail, and SLA tracking.
Yes. After approval, smartWorkflow can auto-provision the role assignment in SAP (via SU01, PFCG, or BAPI/RFC). What-if analysis runs before provisioning: shows the resulting effective authorizations, SoD impact, and SoD conflict alerts. If a conflict would be created, the workflow blocks or escalates per the configured policy.
smartWorkflow integrates bidirectionally with ServiceNow, Jira Service Management, and most ITSM tools via REST API. Pattern: ticket created in ITSM triggers smartWorkflow approval; smartWorkflow updates ticket with approval decision and provisioning status. This keeps the user-facing ticket experience in your existing ITSM while access governance happens in smartGRC.
smartWorkflow supports single-approver, dual approval (four-eyes), tri-party approval, and conditional escalation based on risk class. Each role can have its own workflow definition - e.g., low-risk roles get single-approver, Firefighter access gets dual approval, SOX-relevant roles get tri-party. Approvals are mobile-friendly (email + clickable approval links).
Yes. The leaver workflow is critical for audit compliance: when HR signals an employee departure, smartWorkflow triggers automatic de-provisioning of all SAP roles within the configured SLA (typically same-day for SOX-relevant). Joiner workflow assigns the "starter pack" of roles based on department/job code from HR. Mover workflow recalculates access when an employee changes departments.
Yes - this is a core compliance requirement. Every workflow step is logged: who requested, who approved, who provisioned, what was provisioned, when. The audit trail is exportable in CSV/XML formats acceptable for Big 4 auditors. Workflow history is retained for the configured period (typically 7 years for SOX-relevant data).
smartWorkflow is included in the Enterprise plan (custom pricing, full governance). Auto-provisioning and what-if simulation are Enterprise-only features. Professional plan includes manual approval workflows without auto-provisioning. See pricing tiers.
Yes: the interactive demo includes the smartWorkflow approval interface with sample requests. For a custom workflow PoC on your actual SAP landscape, contact us for a 30-day pilot.
Try the interactive UX preview - no signup, no credit card.