auto_awesome Our AI vision · 18-month roadmap

30 AI agents for SAP access governance & security

We are building a GRC platform where AI agents handle the routine work continuously, escalate the cases that need a human, and let your team focus on what matters. Below: the full catalog of agents shaping our roadmap.

Some capabilities are live today. Others are in active development. We share the full direction so you know where we are heading.

groups Human-in-the-loop

Agents work alongside your team, not instead of it

visibility
Continuous observation
Agents monitor access, sessions and risk signals 24/7 with full audit trail.
bolt
Autonomous on low-risk
Routine, well-understood actions handled by the agent in seconds.
escalator_warning
Escalates to humans
Anything ambiguous, high-risk or precedent-setting goes to your team.
verified
Humans stay in control
Every agent decision is explainable, reviewable and reversible.
Product logic · analyse · score · fix

The three flows the agents run against

Three questions, one platform: why is there a risk, what is it worth, and how do I fix it. The flows are built into the data model - causation, quantitative scoring, and executable remediation. The 19 agents below act inside these flows: recommending the highest-impact fix, previewing score impact, orchestrating human-in-the-loop where needed. The logic is the platform's; AI makes it faster.

?

Why is there a risk?

Deep-dive 7 layers down - for the auditor and the architect.

  1. 1.Identification - risk code (R### SoD / A### SAT), level, narrative
  2. 2.Conflict sides - the two function groups (e.g. "Vendor Master Data ⟷ Payments")
  3. 3.Colliding functions - named, not codes ("Post Vendor Invoice", not FB60)
  4. 4.Source roles - which roles grant each side (the real remediation target)
  5. 5.Toxic role detection - one role that grants both sides on its own (worst case)
  6. 6.Sole-source analysis - for each role, how many users get one side only from it
  7. 7.Technical evidence - Object · Field · Value at the auth-object level
Every layer sortable by Contribution - how much of the Risk Score each element accounts for.
Σ

What is the risk worth?

Quantitative Risk Score - no new scales. Weight = SAP's own Risk.score field (0-100).

Per user
Σ Risk.score across their SoD + SAT risks
How much risk this person carries.
Per role
Σ (Risk.score × affected users)
Exposure - rewards fixing mass-assigned roles first.
Per organisation
Σ Risk.score across (user × risk) pairs
Total risk sitting in the humans.
Level bands
LOW ≤40 MED ≤75 HIGH ≤95 CRIT ≤100
Δ vs last analysis run · historical trend per run · remediation potential = Σ Risk.score of sole-source pairs.

How do I fix it?

A remediation ladder from cheapest to structural. AI recommends the highest-impact move first.

  1. 1.Revoke sole-source role - cheapest, highest ROI. Conflict disappears for the users who got that side only from this role.
  2. 2.Split toxic role - redesign so one role never grants both sides.
  3. 3.Remove function from group - fixes everyone with that role (role-project level).
  4. 4.Remove role from user - fixes one person (assignment level).
  5. 5.Mitigate - compensating control with owner + audit trail (never a silent accept).
auto_awesomeAI engine ranks the highest-impact move: "revoke action X → fixes N conflicts for M users"
forward_to_inboxExecution via ServiceNow ticket - never ad-hoc changes in the tool
fact_checkVerification - Δ score visible after the next analysis run
Live from a customer role

One line. Actionable.

Role ZALL_BC_RFC_BENUTZER ships with 21 conflicts, 38 critical accesses, held by 53 users. smartGRC's AI recommendation:

"Removing the Customer Invoice Posting (SD) action resolves 5 conflicts for 43 users."

Score: 1,978
Remediation potential: −302
Users impacted: 43 of 53

No two-week analysis engagement. No PDF report. Quantified, executable, verifiable.

19 AI agents
Named
Each with a defined autonomy level: monitor · assist · execute. Covering role design, SoD monitoring, anomaly detection, access review, onboarding.
Meet the 19 agents below arrow_forward
Full catalog

30 agents, organised by module

Click any agent for a deep-dive: the challenge it solves, how it works (human-in-the-loop), a mockup from the platform, sample reasoning and expected impact.

smartSecurity

smartSecurity · AI-agented SAP security monitoring

New
priority_high
auto_awesome

Priority Advisor

Ranks findings by risk and business context. Directs owner attention to what matters this week.

verified_user
auto_awesome

Baseline Monitor

Daily RFC scans vs. SBT, SAP Default or custom benchmark. Score 0-100 per system with trend explanation.

healing
auto_awesome

Patch Advisor

Prioritizes SAP Security Notes by CVSS, exposure and system risk. Recommends patching order per Basis team.

gavel
auto_awesome

Compliance Advisor

Auto-maps every finding to NIS2 Art. 21, ISO 27001 Annex A, GDPR Art. 32, DORA Art. 9-10 controls.

bug_report
auto_awesome

Vulnerability Analyst

CVE correlation, exploitability scoring per system. Surfaces findings most likely flagged in external pentest.

history_edu
auto_awesome

Exception Reviewer

Assesses exception risk, suggests compensating controls, flags risky approvals with expiry tracking.

psychology
auto_awesome

Risk Summarizer

One-paragraph executive summary of current security risk - updated after each scan for CISO briefing.

radar
auto_awesome

Change Monitor

Watches for unauthorized configuration changes between scans and alerts immediately with change trail.

shield_lock
auto_awesome

Security Notes Agent

Tracks all SAP Security Notes per system, escalates unpatched CVSS 9+ Notes to Patch Advisor + SIEM.

person_add
auto_awesome

User Lifecycle Agent

Detects offboarding gaps - accounts still active after HR termination event. Auto-flags SAP_ALL holders.

forward_to_inbox
auto_awesome

SIEM Push Agent

Real-time push of CRITICAL/HIGH findings to Splunk (HEC), Microsoft Sentinel, ServiceNow with full context.

Trust & governance

Built for auditable AI

In regulated industries, "the AI did it" is not an acceptable answer. Every agent in smartGRC is designed to be explainable, controllable and reversible.

history

Audit trail

Every agent decision logged with input, reasoning and outcome. Auditor-ready.

visibility

Explainability

Agent always shows its work: facts considered, rules matched, confidence score.

tune

Configurable thresholds

You decide what gets auto-handled and what gets escalated. No hidden defaults.

undo

Reversible

Every agent action can be reverted - by a human, at any point in the timeline.

SOX 404 / ITGC

Agent decisions tested as IT general controls. Sample evidence on demand.

GDPR Article 22

Human-in-the-loop by design: no fully automated decisions affecting individuals.

ISO 27001 / SOC 2

Agent operations included in the platform's certification scope.

Who builds this

Built by GRC Advisory - SAP audit experience, not AI hype

smartGRC is not an AI-first startup pivoting into compliance. It is built by GRC Advisory, a SAP GRC consulting firm with 15+ years of experience auditing and securing SAP landscapes for enterprise customers across DACH, CEE and beyond. The 30 AI agents in this hub are designed by the people who have actually closed SOX findings, run Firefighter reviews and defended SoD risk registers in front of external auditors.

history_edu
15+

Years of SAP GRC consulting

Hands-on SOX 404, ITGC, GDPR Article 32 engagements. We have built the audit workflows we are now automating.

groups
50+

Enterprise SAP customers

Volkswagen, AmRest, Cyfrowy Polsat, PCC Rokita, InPost and others trust the platform in production SAP landscapes.

verified
Verified

SAP Service Partner

Listed on SAP Partner Finder. Direct technical access to SAP for integration patterns, certified consultants on staff.

shield_lock

Why this matters for your AI decision

When auditors ask "who designed your AI controls?", the answer matters. Our consultants sit on both sides of the SOX 404 table - they design the controls and they have defended them. The 4-level autonomy dial reflects that experience, not a generic LLM wrapper.

Become a design partner

We are looking for SAP-running enterprises to co-design the agents that matter most. Get early access, shape the roadmap, and influence what gets built first.