You can run a complete SAP SoD analysis without any access to the production system. MTC Skopos reads standard SAP table exports (USR02, AGR_USERS, AGR_1251, UST12) fully offline: no RFC connection, no agent, no cloud upload. The extraction takes 5 to 10 minutes, the analysis of a 10,000-user system finishes in under 2 minutes, and the included template ruleset covers 350+ SoD risks and 700+ critical access checks at authorization-object level. Licensing is a flat €5,736/year.

Offline analysis with MTC Skopos
Production access neededNone: no account, no RFC, no agent
InputStandard table exports (USR02, AGR_USERS, AGR_1251, UST12)
Extraction time5 to 10 minutes manually, 1 to 5 minutes via RFC where available
Analysis timeUnder 10 seconds for a typical 2,500-user system*, under 2 minutes for 10,000 users
Checks included350+ SoD risks, 700+ critical access, 100+ authorization quality checks
DepthAuthorization-object level, including organizational values
Data locationStays on the machine running the analysis, no telemetry
PricingFrom €5,736/year flat, unlimited systems and users analyzed

* Benchmark: 150+ high and critical SoD risks in scope.

How do I run SoD analysis without access to the production SAP system?

Three steps, no production footprint:

  1. Extract. Whoever has SAP access (the Basis team, the client, a colleague with display authorization) exports the standard authorization tables. MTC Skopos ships with an extraction guide; the manual export takes 5 to 10 minutes. Where an RFC connection is acceptable, a secured function module pulls the same tables in 1 to 5 minutes.
  2. Load. Copy the exports to any Windows laptop and open them in MTC Skopos. The application is a portable executable, so there is nothing to install or approve.
  3. Analyze. A full run on a 10,000-user system completes in under 2 minutes against the included ruleset or your own. From receiving the exports to reviewing findings is under 15 minutes.

The same workflow drives the broader access risk analysis capability set: SoD conflicts, critical access, over-privileged users, and organizational scope checks all come from the one extraction.

Which SAP tables are needed?

Four tables carry the authorization picture: user master data (USR02), role assignments (AGR_USERS), role authorization values (AGR_1251), and user-level authorizations (UST12). For did-do evidence, add transaction usage statistics (ST03N/STAD) and change documents (CDHDR/CDPOS). All of them are standard, read-only exports that require no system change and no customizing.

Is offline analysis as accurate as a tool running inside SAP?

Yes, because the exported tables are the same data SAP itself evaluates when it performs an authority check. MTC Skopos analyzes them at authorization-object level, so a user who holds FB60 but is locked out of the relevant company codes is not reported as a false positive. The one honest caveat: findings describe the system as of the extraction date. Since a re-extraction plus re-run takes under 15 minutes, refreshing the picture during an engagement is routine rather than a scheduling problem.

When is working offline the right approach?

  • No production access policy. Security or works-council rules keep third parties, and often internal analysts, out of production. Offline analysis respects that without weakening the test.
  • Audit independence. Auditors test against a ruleset they control instead of reading reports from the client's own GRC configuration. The auditor workflow builds on exactly this.
  • Consulting engagements. Nothing is installed in the client landscape and nothing is left behind. See the consultant setup.
  • Confidentiality-sensitive environments. Banks, defense, and public sector often cannot send authorization data to a cloud analyzer. Here the data never leaves the machine you choose.
  • Before a GRC project. Measuring the real conflict count before scoping SAP GRC or Pathlock avoids sizing the project on guesses. The bridge-to-GRC playbook covers this path.

What does it cost?

A flat €5,736/year for the base license, €555 per additional seat, with no per-system or per-user fees: one license covers every system you analyze offline. Optional add-ons such as Did-Do Analysis are priced openly on the pricing page, and a 14-day trial runs on your own exports. For how this compares to connected GRC suites, see the 13 SAP SoD tools comparison.

Frequently asked questions

How do I run SoD analysis without access to the production SAP system?

Export the standard authorization tables (USR02, AGR_USERS, AGR_1251, UST12) from the SAP system, then load them into MTC Skopos on any Windows laptop. The manual export takes 5 to 10 minutes and the analysis of a 10,000-user system completes in under 2 minutes, so you go from extraction to findings in under 15 minutes without any production account, RFC connection, or installed agent.

Is offline SoD analysis as accurate as running a tool inside SAP?

Yes. The exported tables contain the same authorization values SAP evaluates at runtime, and MTC Skopos analyzes them at authorization-object level, including organizational values. The result is identical to what a connected analysis of the same snapshot would produce; the only difference is that findings reflect the extraction date rather than a live view.

What risks are checked in an offline analysis?

MTC Skopos ships with a template ruleset of 350+ SoD risks, 700+ critical access checks, and 100+ authorization quality checks such as organizational value coverage and maintenance activities hiding in display roles. The ruleset is editable down to authorization-object level, and you can import your own or your client's ruleset instead.

Can I get did-do evidence without a production connection?

Yes. Adding transaction usage statistics (ST03N/STAD exports) and change documents (CDHDR/CDPOS) to the extraction lets the Did-Do Analysis add-on show which conflicting access was actually exercised, all still offline.

Does the SAP data get uploaded anywhere during the analysis?

No. MTC Skopos is a portable desktop application with no hosted component and no telemetry. The authorization data stays on the machine running the analysis, which keeps security review of the approach short: there is no cloud processor to assess.


Related reading: SAP Access Risk Analysis · SoD tool for auditors · SoD tool for consultants · Multi-ERP SoD analysis · 13 SAP SoD tools compared