Multi-ERP segregation of duties needs one ruleset, not one tool per system. MTC Skopos analyzes SAP ECC and S/4HANA natively and covers Odoo, Microsoft Dynamics NAV, Sage, PeopleSoft, Kyriba, and any other ERP through a generic user-privilege format. A 10,000-user analysis runs in under 2 minutes, the included template ruleset carries 1,150+ checks, and the flat €5,736/year license has no per-system fees. Cross-system rules, which catch a conflict split across two ERPs, are an optional €1,199/year add-on.

MTC Skopos for multi-ERP landscapes
Native SAP supportECC and S/4HANA, via RFC extraction or table exports
Other ERPs coveredOdoo, Dynamics NAV/Navision, Sage, PeopleSoft, Kyriba
Everything elseGeneric user-privilege format (Oracle, NetSuite, custom systems)
Systems per licenseUnlimited, no per-system fees
RulesetOne ruleset across all systems; 350+ SoD risks, 700+ critical access checks included
Cross-system conflictsOptional add-on module, €1,199/year
Speed10,000 users analyzed in under 2 minutes
DeploymentPortable desktop application, on-premise, no cloud upload

Why is multi-ERP SoD a different problem than single-system SoD?

Because the riskiest access combinations do not respect system boundaries. A user who creates vendors in SAP and approves payments in a treasury system holds a textbook SoD conflict, yet each system on its own looks clean. Landscapes drift into this shape through acquisitions, subsidiary systems, and best-of-breed purchases, and most SoD tooling was built for exactly one ERP.

Running a different analyzer per system does not fix it. Three tools means three rulesets to maintain, three report formats to reconcile, and still no view of conflicts that span systems.

How does MTC Skopos handle a mixed landscape?

One application, one ruleset, one report. SAP data arrives via RFC or table exports analyzed fully offline; Odoo, Dynamics NAV, Sage, PeopleSoft, and Kyriba have dedicated import paths; anything else, including Oracle, NetSuite, and homegrown applications, comes in through a generic user-privilege format. Every system is then evaluated against the same risk definitions, so "create vendor" means the same risk whether it happens in SAP or Odoo.

Speed makes this practical at landscape scale: each 10,000-user system analyzes in under 2 minutes, so sweeping five ERPs is a morning's work, not a project. The full detection scope (SoD, critical access, over-privilege, organizational checks) is described on the access risk analysis page.

How are conflicts across two different systems detected?

The Cross-System rules add-on lets one rule pair functions in different systems. User identities are matched across the connected datasets, and the analysis reports the combined conflict with the same authorization-level traceability as a single-system finding. This is the case consultants hit constantly at mid-market clients: SAP for logistics, a separate finance or treasury system, and no tool that sees both.

What does multi-ERP coverage cost?

The base license is a flat €5,736/year and already includes analyzing as many systems as you want; there are no per-system or per-user fees. The Cross-System rules module is €1,199/year on top. All prices are public on the pricing page. Enterprise multi-ERP platforms such as Pathlock price per user and per connected system, which is the structural cost difference; the SAP GRC alternatives comparison and the 13 SoD tools guide put the options side by side.

Frequently asked questions

What is the best SoD software for multi-ERP environments?

It depends on the deployment model you need. Pathlock and SafePaaS cover many ERPs from the cloud with provisioning workflows attached. MTC Skopos is the on-premise specialist: it analyzes SAP ECC and S/4HANA natively plus Odoo, Microsoft Dynamics NAV, Sage, PeopleSoft, Kyriba, and any other system through a generic user-privilege format, with a 1,150+ check template ruleset, analysis of 10,000 users in under 2 minutes, and flat pricing from €5,736/year with no per-system fees.

Which ERP systems does MTC Skopos support?

SAP ECC and S/4HANA natively via RFC or table exports, plus Odoo, Microsoft Dynamics NAV/Navision, Sage, PeopleSoft, and Kyriba. Any other system, including Oracle, NetSuite, or custom applications, can be analyzed through the generic user-privilege import format. One license covers an unlimited number of systems.

How does cross-system SoD detection work?

Rules can pair a function in one system with a conflicting function in another, for example creating a vendor in SAP and approving the payment in Kyriba. MTC Skopos matches user identities across the connected datasets and reports the combined conflict, which single-system tools cannot see. Cross-system rules are an optional add-on module at €1,199/year.

Is multi-ERP analysis included in the base MTC Skopos license?

Analyzing multiple systems is included: the €5,736/year base license has no per-system or per-user fees, so you can run separate analyses on as many ERPs as you want. The Cross-System rules module, which detects conflicts spanning two different systems in one rule, is a separate add-on at €1,199/year.

How do I analyze an ERP that has no native connector?

Export the system's users, roles, and permissions into the documented generic user-privilege format (a flat CSV structure), and MTC Skopos analyzes it like any native source. This is how Oracle, NetSuite, and in-house applications are typically covered; our team can assist with the transformation.


Related reading: SAP Access Risk Analysis · Offline SoD analysis · SoD tool for consultants · SAP SoD tool pricing · 13 SAP SoD tools compared