You can check SoD conflicts in SAP without GRC and without any access to the production system. No GRC license, no server, no implementation project. MTC Skopos reads standard SAP table exports (USR02, AGR_USERS, AGR_1251, UST12) fully offline: no RFC connection, no agent, no cloud upload. The extraction takes 5 to 10 minutes, the analysis of a 10,000-user system finishes in under 2 minutes, and the included template ruleset covers 350+ SoD risks and 700+ critical access checks at authorization-object level. Licensing is a flat €5,736/year.

Offline analysis with MTC Skopos
Production access neededNone: no account, no RFC, no agent
InputStandard table exports (USR02, AGR_USERS, AGR_1251, UST12)
Extraction time5 to 10 minutes manually, 1 to 5 minutes via RFC where available
Analysis timeUnder 10 seconds for a typical 2,500-user system*, under 2 minutes for 10,000 users
Checks included350+ SoD risks, 700+ critical access, 100+ authorization quality checks
DepthAuthorization-object level, including organizational values
Data locationStays on the machine running the analysis, no telemetry
PricingFrom €5,736/year flat, unlimited systems and users analyzed

* Benchmark: 150+ high and critical SoD risks in scope.

How do I run SoD analysis without access to the production SAP system?

Three steps, no production footprint:

  1. Extract. Whoever has SAP access (the Basis team, the client, a colleague with display authorization) exports the standard authorization tables. MTC Skopos ships with an extraction guide; the manual export takes 5 to 10 minutes. Where an RFC connection is acceptable, a secured function module pulls the same tables in 1 to 5 minutes.
  2. Load. Copy the exports to any Windows laptop and open them in MTC Skopos. The application is a portable executable, so there is nothing to install or approve.
  3. Analyze. A full run on a 10,000-user system completes in under 2 minutes against the included ruleset or your own. From receiving the exports to reviewing findings is under 15 minutes.

The same workflow drives the broader access risk analysis capability set: SoD conflicts, critical access, over-privileged users, and organizational scope checks all come from the one extraction.

How do I check SoD conflicts in SAP without GRC?

You do not need SAP GRC, or any server-side tooling, to test for SoD conflicts. Export the standard authorization tables, load them into MTC Skopos on a laptop, and run the analysis against the included template ruleset of 350+ SoD risks and 700+ critical access checks. There is no GRC license, no implementation project and no configuration: a 10,000-user system completes in under 2 minutes at authorization-object level, which is the same depth a GRC suite evaluates at.

The distinction worth keeping straight is that GRC suites bundle risk analysis with provisioning, approval workflow and emergency access. Skipping the suite means skipping those three, not skipping the detection. If you are heading toward a GRC project anyway, measuring the real conflict count first is covered in the bridge-to-GRC playbook, and the fuller argument for a specialist is in the case for a specialist over a suite.

Which SAP tables are needed?

Four tables carry the authorization picture: user master data (USR02), role assignments (AGR_USERS), role authorization values (AGR_1251), and user-level authorizations (UST12). For did-do evidence, add transaction usage statistics (ST03N/STAD) and change documents (CDHDR/CDPOS). All of them are standard, read-only exports that require no system change and no customizing.

Is offline analysis as accurate as a tool running inside SAP?

Yes, because the exported tables are the same data SAP itself evaluates when it performs an authority check. MTC Skopos analyzes them at authorization-object level, so a user who holds FB60 but is locked out of the relevant company codes is not reported as a false positive. The one honest caveat: findings describe the system as of the extraction date. Since a re-extraction plus re-run takes under 15 minutes, refreshing the picture during an engagement is routine rather than a scheduling problem.

When is working offline the right approach?

  • No production access policy. Security or works-council rules keep third parties, and often internal analysts, out of production. Offline analysis respects that without weakening the test.
  • Audit independence. Auditors test against a ruleset they control instead of reading reports from the client's own GRC configuration. The auditor workflow builds on exactly this.
  • Consulting engagements. Nothing is installed in the client landscape and nothing is left behind. See the consultant setup.
  • Confidentiality-sensitive environments. Banks, defense, and public sector often cannot send authorization data to a cloud analyzer. Here the data never leaves the machine you choose.
  • Before a GRC project. Measuring the real conflict count before scoping SAP GRC or Pathlock avoids sizing the project on guesses. The bridge-to-GRC playbook covers this path.

What does it cost?

A flat €5,736/year for the base license, €555 per additional seat, with no per-system or per-user fees: one license covers every system you analyze offline. Optional add-ons such as Did-Do Analysis are priced openly on the pricing page, and a 14-day trial runs on your own exports. For how this compares to connected GRC suites, see the 13 SAP SoD tools comparison.

Frequently asked questions

How do I run SoD analysis without access to the production SAP system?

Export the standard authorization tables (USR02, AGR_USERS, AGR_1251, UST12) from the SAP system, then load them into MTC Skopos on any Windows laptop. The manual export takes 5 to 10 minutes and the analysis of a 10,000-user system completes in under 2 minutes, so you go from extraction to findings in under 15 minutes without any production account, RFC connection, or installed agent.

How do I check SoD conflicts in SAP without GRC?

You do not need SAP GRC, or any server-side tooling, to test for SoD conflicts. Export the standard authorization tables, load them into MTC Skopos on a laptop, and run the analysis against the included template ruleset of 350+ SoD risks and 700+ critical access checks. There is no GRC license, no implementation project and no configuration: a 10,000-user system completes in under 2 minutes at authorization-object level, which is the same depth a GRC suite evaluates at.

Is offline SoD analysis as accurate as running a tool inside SAP?

Yes. The exported tables contain the same authorization values SAP evaluates at runtime, and MTC Skopos analyzes them at authorization-object level, including organizational values. The result is identical to what a connected analysis of the same snapshot would produce; the only difference is that findings reflect the extraction date rather than a live view.

What risks are checked in an offline analysis?

MTC Skopos ships with a template ruleset of 350+ SoD risks, 700+ critical access checks, and 100+ authorization quality checks such as organizational value coverage and maintenance activities hiding in display roles. The ruleset is editable down to authorization-object level, and you can import your own or your client's ruleset instead.

Can I get did-do evidence without a production connection?

Yes. Adding transaction usage statistics (ST03N/STAD exports) and change documents (CDHDR/CDPOS) to the extraction lets the Did-Do Analysis add-on show which conflicting access was actually exercised, all still offline.

Does the SAP data get uploaded anywhere during the analysis?

No. MTC Skopos is a portable desktop application with no hosted component and no telemetry. The authorization data stays on the machine running the analysis, which keeps security review of the approach short: there is no cloud processor to assess.


Related reading: SAP Access Risk Analysis · SoD tool for auditors · SoD tool for consultants · Multi-ERP SoD analysis · 13 SAP SoD tools compared