Segregation of Duties Software for SAP & ERP Systems

MTC Skopos is a portable SAP SoD tool for access risk analysis and ERP segregation of duties that runs on your own laptop and covers unlimited systems and users on one licence.

Run an SoD analysis on SAP or any other ERP, find Critical Access and conflicts, and get a remediation plan. Extraction to findings takes under 15 minutes.

Use MTC Skopos for free

14 days free trial - no commitment

MTC Skopos demo video
Watch on YouTube

MTC Skopos is a portable SAP SoD tool for access risk analysis and ERP segregation of duties. It detects SoD conflicts and critical access at authorization-object level in minutes, then goes further than most GRC suites by generating step-by-step remediation plans ranked by business impacts.

Fast, smooth and affordable Access governance

Traditional GRC tools are slow and complex

Servers, consultants, months of setup and still, running a full SoD analysis takes hours or days.

→ Download, connect, analyze in minutes. No infrastructure.

Changes introduce new risks

Every role modification or user provisioning can create new SoD conflicts. Without simulation, you only find out after the fact.

→ Simulate changes before applying them. See risk impact instantly.

Remediation is guesswork

Knowing you have conflicts is one thing. Knowing which changes won't break business operations is another.

→ Get step-by-step remediation plans ranked by business impact.

Automated SoD Analysis in 3 Simple Steps

Automate your Segregation of Duties process - from download to comprehensive risk remediation in minutes, not months

1

Download & Run

Get the lightweight portable application. No servers, no complex setup, no installation, no IT project required.

2

Connect Your Data

Import via SAP RFC connection or CSV export from any ERP system. Your data stays on your machine.

3

Analyze & Remediate

Get instant SoD analysis, identify violations, and receive actionable remediation recommendations.

Efficient and Comprehensive Risk Analysis

Find and fix Segregation of Duties and critical access risks across SAP and your other ERPs. The template ruleset has 1,150+ checks, and you can read and change every one of them.

Segregation of Duties Conflict Detection

MTC Skopos detects SoD conflicts in SAP and any ERP, and applies organizational scope before it reports one: a user who creates vendors in company code 1000 and pays them in 2000 is not flagged. Derived roles and validity dates are resolved as well, so an expired assignment or an out-of-scope derivation never turns into a finding. You spend less time dismissing false positives, and the findings left are real ones. Why the depth of analysis changes the result

Template Ruleset Included

MTC Skopos ships with 350+ SoD risks, 700+ critical access checks and 100+ authorization quality checks (organizational values, maintenance activities in display roles). That is 1,150+ checks on the first run.

Treat it as a template. Review it and tune it to your own processes before you rely on the results. It also converts to SAP GRC format, so if you move to GRC later, your ruleset goes with you. Ruleset maintenance

Permission Simulation

Test role and authorization changes before applying them to production using simulation feature.
See exactly how changes will impact user access and identify potential access risks.
Simulate with Confidence:

  • Adding or removing user role assignments
  • Adding or removing authorization within existing roles
  • Creating new role
  • Cross-system access combinations and their security implications
Preview, validate, then deploy - ensuring every access change enhances security rather than creating vulnerabilities.

Advanced Remediation

Finding a conflict is the easy part. For each one, MTC Skopos proposes a fix: which role assignment to remove or replace, and in what order, based on criteria you set. It looks at usage data first, so it can tell access nobody uses, which can go today, from access a process still depends on. How it works

Remediation Reports put that plan into a document for role owners and auditors to sign off. Learn about AI remediation

Did-Do Analysis

SAP GRC does can-do. We do did-do. Traditional tools show who could exploit a conflict. MTC Skopos shows who actually did by correlating access with change documents. Focus remediation on risks that materialized, not theoretical violations. See how it works

Cross-System Risk Detection

Assess risks arising from access across multiple systems, and identify critical combinations that span different platforms.

IAM Business Role Analysis

Your IAM assigns the access. We analyze the risk. Import business roles from Microsoft Entra, SailPoint, or ServiceNow and detect SoD conflicts in the access they grant, across every connected system. Every risk shows the business role behind it, and you can simulate bundle changes before touching the IAM. Analysis only. See how it works

Ground Truth for Your AI

Give a model a raw authorization export and it will answer with confidence. It won't know that a role grants a transaction without the authorization object behind it, or that an assignment expired last quarter. MTC Skopos sorts that out first: composite and derived roles are expanded, validity dates and organizational scope are applied, and only then does a model see the data.

You pick the model. Claude, ChatGPT or any stdio-compatible client can query the results through the MCP server. The built-in assistant works with any OpenAI-compatible API on your own key. With a local LLM, nothing leaves your network. User, role and system names are anonymized before they reach any model. Explore AI integration

SAP Role Designer (AI)

Describe your requirements to our AI and automatically generate optimal role designs with default authorization configurations.

Data Sovereignty

Your SAP authorization data stays on your network.
MTC Skopos is a desktop application with no cloud component. Nothing is sent to MTC or stored by a third party. The data stays on your machines under your own security policies, which a SaaS GRC tool can't offer.
*SAP RFC connection may traverse your network; all analysis runs locally.

Also Included

The rest of what you'd expect from an SoD tool:

  • Users and roles analysis, by role or by user, including overprovisioning and the FUE licence impact of each user and role
  • User & Role Explorer for browsing your authorization concept. It stays fast on large systems
  • Executive reporting: each analysis opens on a dashboard of conflicts by risk level and business process, the most frequent risks and the users with the most conflicts. Click a risk to see the actions behind it. A Microsoft Power BI report (.pbix) is included. See reporting capabilities
  • JSON and CSV exports that load directly into Power BI, Tableau, Python or R, compact enough to keep AI token costs low
  • Speed: a single-user check in under a second, a full 10,000-user system in under two minutes on a standard laptop. Why we built this

SAP & ERP System Compatibility

Works with your existing IT landscape

If there's data, MTC Skopos can analyse it.

SAP Systems

Direct RFC connection or bucket folder import.
Full support for SAP authorization objects, role and profile structures.

Any System

Generic User-Privilege format supports any system. Data imported via bucket folder import.
We assist with data transformation and setup.

Minutes

Full system analysis completed

Zero

Servers or infrastructure required

100%

Data stays on your machine

Any ERP

SAP, Odoo, Navision & more

Built for compliance, security, and risk management

Comprehensive access risk analysis from detection to remediation

Your SAP Risk Data Never Leaves Your Infrastructure

Unlike SaaS GRC solutions, MTC Skopos runs entirely on your machine. No cloud uploads. No third-party data processing. No vendor access to your authorization data. Your sensitive access patterns stay where they belong: under your control.

Why Not SAP GRC Access Control?

Traditional GRC tools were built for a different era. Here's how MTC Skopos compares.

MTC Skopos SAP GRC / Traditional Tools
Deployment Minutes (portable app) 3-6 months implementation
Infrastructure None required Servers, database, middleware
Data Sovereignty 100% local, never leaves your network Cloud or vendor-hosted
Analysis Speed Full system in minutes Hours to days
Analysis Type Did-do (actual execution) Can-do only (theoretical)
AI Integration Native MCP + local LLM support Limited or none
Cost Model Simple annual license Per-population monitored + implementation + support

Why GRC & compliance teams choose MTC Skopos

Minutes, not weeks

Go from weeks of manual SoD review to comprehensive reports in minutes. Simulate role changes first, so new conflicts are caught before they reach production.

Live the same day

No 6-month rollout. Download the portable app, connect your SAP system over RFC, and get actionable access risk results the same day.

Risk across systems

Cross-system analysis surfaces toxic combinations that span SAP and connected systems like treasury, not just a single ERP.

Flexible Licences

Configure your plan and see your price instantly.

MTC Skopos costs €5,736 per year for the base license, with one seat included. Additional seats are €555 each per year. The add-ons (remediation report, did-do analysis, simulation, cross-system, IAM business roles) are optional and priced separately, and the fully loaded configuration with all of them enabled comes to €13,198 per year.

Compare that with the alternatives. One wrong SoD conclusion found in an external audit costs more than the licence. So do weeks of analyst time spent on false positives, or rebuilding the in-house script after the person who wrote it leaves. Run the ROI calculator.

Monthly Yearly

Business

Core features with optional add-ons

13.198

per year (10% discount on yearly subscription)

Start for free

Displayed prices exclude applicable VAT or tariffs.

Need help with ruleset configuration, data preparation, or remediation? View our consulting services

Calculate your ROI to estimate the savings for your organisation.

Built for Compliance, Security & Audit Teams

Whether you're managing SoD compliance, access risk, or consulting, MTC Skopos adapts to your workflow

Compliance & Internal Audit

Manual SoD reviews that take weeks and miss authorization-level risk
✓ Automated SAP SoD analysis with audit-ready evidence in minutes

Run Critical Access, SoD, and did-do checks against your own ruleset, and export reports your auditors and SOX testers can sign off on.

SAP Security & Authorizations

Role changes that introduce new SoD conflicts you find out about too late
✓ Simulate the risk impact of every role change before you ship it

Get clean and stay clean. Test authorization changes against your ruleset and screen access during provisioning, so new conflicts never reach production.

Auditors & Consultants

Re-running access risk analysis across many client systems, fast
✓ Portable SoD tool with same-day insights on any client landscape

Download, connect or import a CSV, and deliver an access risk analysis the same day. No server, no client-side install, nothing left behind.

CISO / CIO

Fragmented risk visibility across SAP and non-SAP ERP
✓ One cross-system view of ERP segregation of duties

See access risk across your whole landscape, not just SAP. Cross-system analysis surfaces toxic combinations that span ERP, treasury, and finance systems.

SAP SoD Tool FAQ

Common questions about access risk analysis and segregation of duties with MTC Skopos

What is the best SAP SoD tool?

The best SAP SoD tool depends on whether you need provisioning workflows or fast, focused analysis and remediation. MTC Skopos is a specialized SAP SoD tool: it runs authorization-object-level segregation of duties analysis in minutes, deploys as a portable desktop app with no server, and goes beyond detection to generate remediation plans. For a feature-by-feature comparison, see our SoD tools guide.

How much does an SAP SoD tool cost?

MTC Skopos starts at €5,736/year for the base license (one seat, billed yearly). Additional seats are €555 each, and optional add-ons cover remediation reports, did-do analysis, simulation, and cross-system analysis. There is a free 14-day trial with no commitment.

Can I run SAP segregation of duties analysis without a server?

Yes. MTC Skopos is a portable SAP SoD tool that runs on your desktop with no server, no agent inside SAP, and no cloud upload. Connect to SAP over RFC or import a CSV, and your authorization data stays on your machine. It is operational the same day, which suits consultants and auditors moving between client systems.

Does MTC Skopos do ERP segregation of duties beyond SAP?

Yes. Beyond SAP, MTC Skopos handles ERP segregation of duties for any system that can export role and user data (Odoo, Microsoft Dynamics, Sage, Oracle PeopleSoft, Kyriba, and more) via CSV import. Cross-system analysis then detects SoD conflicts that span several ERPs at once.

How is MTC Skopos different from SAP GRC Access Control?

The main difference is focus: MTC Skopos is built around remediation, not only detection. Where SAP GRC Access Control centers on detecting risk and provisioning access, MTC Skopos goes a step further and generates step-by-step remediation plans ranked by business impact, so teams can resolve SoD conflicts instead of just reporting them. It runs as a portable analyzer that returns authorization-level results in minutes. See our remediation white paper for the approach.

How long does an SAP SoD analysis take?

An SAP SoD analysis with MTC Skopos completes in minutes, not the hours or days typical of server-based GRC suites. You download the app, connect over RFC or import a CSV, run the analysis against your ruleset, and get conflict detection plus remediation recommendations in the same session.

Struggling to choose the best GRC tool?

Chat with your favorite AI chat assistant or book a demo to learn more about MTC Skopos and how it can help your business!

Ready to Secure Your ERP Systems?

Join forward-thinking companies using MTC Skopos for comprehensive access risk management

Use MTC Skopos for free

14 days free trial - no commitment