Field Notes: Articles & Insights

A founder's notes from selling an offline SAP access-risk tool: how organisations actually evaluate, buy, and trust SoD tooling.

Found 7 articles in this category.

All Articles in "Field Notes"

Two Years of Watching Companies Decide How to Handle SAP Access Risk
2026-08-19

MTC Skopos was built to do consulting work at clients who had no access-risk tooling, by a security consultant and a software architect, and it grew to cover the analyses we were rebuilding in Python, SQL and Alteryx on every engagement: did-do, remediation, the authorization matrix, the role bill of materials. Then it started selling, to global firms, Big Four, boutiques, public bodies and S&P 500 companies. This introduces Field Notes, a six-part series on how those organisations actually evaluate and buy SoD tooling.

We Built a Desktop SoD Tool in 2024. Here Is the Boring Reason Why.
2026-08-19

Field Notes article 2. The decision to ship MTC Skopos as a signed portable executable came from the consultant's laptop problem: locked-down client machines where nothing can be installed, so the analysis is either a spreadsheet that stops at transaction level or a SQL, Python or Alteryx build that is correct once and thrown away at the end of the engagement. What portable-and-signed solves, why the product is still sold as a subscription when there is nothing hosted, and where SaaS honestly wins.

Two Kinds of SoD Buyer, and Why One of Them Never Answers Your Email Again
2026-08-19

Field Notes article 3. Compliance-driven buyers need a defensible SoD report once, to close an audit finding, and then the need is gone. Efficiency-driven buyers produce that report repeatedly and it hurts. Both look identical during a trial. Three first-call questions that separate them, the trial-extension mistake we made for six months, and what happens after the yes, when the file moves to a procurement function that never saw the product.

They Already Own SAP GRC Access Control. They Are Still Shopping.
2026-08-19

Field Notes article 4. Large enterprises with fully deployed SAP GRC Access Control kept asking for demos, and so did organisations already running a specialist analyzer such as CSI tools. They were not confused. Detection works; what is missing is everything after the report lands: remediation decisions, fast exploratory simulation, and output a business owner will read. The Excel file every security architect maintains is the market.

Send Us Your SOC 2 Report. But We Never Receive Your Data.
2026-08-19

Field Notes article 5. Procurement asks an offline desktop tool for a SOC 2 report. The request is not unreasonable: certificates are a proxy for working processes, and a compromised build pipeline is a real risk. But the scope does not fit software whose boundary never contains customer data. What we offer instead: verifiable code signing, packet-capture-testable data flow, Ed25519-signed logs, an SBOM embedded in the binary, and the five questions security teams should ask in place of the certificate.

What If You Disappear? It Is a Good Question. Ask It of Everyone.
2026-08-19

Field Notes article 6, closing the series. Every small vendor gets the disappearance question, and the honest answer splits it into four risks: operational continuity, data access, licensing, and maintenance. Three structurally favour local software; one genuinely does not. Software mostly disappears by sunset, acquisition and forced migration rather than by bankruptcy, which is a risk vendor size does not remove. What MTC Skopos commits to: if the company stops, the version you paid for keeps running, with no licence server in the way.

Want to learn more about ERP access risk management? Explore MTC Skopos features for comprehensive Segregation of Duties analysis and remediation.

MTC Skopos © 2026