You can run a complete SAP SoD analysis without any access to the production system. MTC Skopos reads standard SAP table exports (USR02, AGR_USERS, AGR_1251, UST12) fully offline: no RFC connection, no agent, no cloud upload. The extraction takes 5 to 10 minutes, the analysis of a 10,000-user system finishes in under 2 minutes, and the included template ruleset covers 350+ SoD risks and 700+ critical access checks at authorization-object level. Licensing is a flat €5,736/year.
| Offline analysis with MTC Skopos | |
|---|---|
| Production access needed | None: no account, no RFC, no agent |
| Input | Standard table exports (USR02, AGR_USERS, AGR_1251, UST12) |
| Extraction time | 5 to 10 minutes manually, 1 to 5 minutes via RFC where available |
| Analysis time | Under 10 seconds for a typical 2,500-user system*, under 2 minutes for 10,000 users |
| Checks included | 350+ SoD risks, 700+ critical access, 100+ authorization quality checks |
| Depth | Authorization-object level, including organizational values |
| Data location | Stays on the machine running the analysis, no telemetry |
| Pricing | From €5,736/year flat, unlimited systems and users analyzed |
* Benchmark: 150+ high and critical SoD risks in scope.
How do I run SoD analysis without access to the production SAP system?
Three steps, no production footprint:
- Extract. Whoever has SAP access (the Basis team, the client, a colleague with display authorization) exports the standard authorization tables. MTC Skopos ships with an extraction guide; the manual export takes 5 to 10 minutes. Where an RFC connection is acceptable, a secured function module pulls the same tables in 1 to 5 minutes.
- Load. Copy the exports to any Windows laptop and open them in MTC Skopos. The application is a portable executable, so there is nothing to install or approve.
- Analyze. A full run on a 10,000-user system completes in under 2 minutes against the included ruleset or your own. From receiving the exports to reviewing findings is under 15 minutes.
The same workflow drives the broader access risk analysis capability set: SoD conflicts, critical access, over-privileged users, and organizational scope checks all come from the one extraction.
Which SAP tables are needed?
Four tables carry the authorization picture: user master data (USR02), role assignments (AGR_USERS), role authorization values (AGR_1251), and user-level authorizations (UST12). For did-do evidence, add transaction usage statistics (ST03N/STAD) and change documents (CDHDR/CDPOS). All of them are standard, read-only exports that require no system change and no customizing.
Is offline analysis as accurate as a tool running inside SAP?
Yes, because the exported tables are the same data SAP itself evaluates when it performs an authority check. MTC Skopos analyzes them at authorization-object level, so a user who holds FB60 but is locked out of the relevant company codes is not reported as a false positive. The one honest caveat: findings describe the system as of the extraction date. Since a re-extraction plus re-run takes under 15 minutes, refreshing the picture during an engagement is routine rather than a scheduling problem.
When is working offline the right approach?
- No production access policy. Security or works-council rules keep third parties, and often internal analysts, out of production. Offline analysis respects that without weakening the test.
- Audit independence. Auditors test against a ruleset they control instead of reading reports from the client's own GRC configuration. The auditor workflow builds on exactly this.
- Consulting engagements. Nothing is installed in the client landscape and nothing is left behind. See the consultant setup.
- Confidentiality-sensitive environments. Banks, defense, and public sector often cannot send authorization data to a cloud analyzer. Here the data never leaves the machine you choose.
- Before a GRC project. Measuring the real conflict count before scoping SAP GRC or Pathlock avoids sizing the project on guesses. The bridge-to-GRC playbook covers this path.
What does it cost?
A flat €5,736/year for the base license, €555 per additional seat, with no per-system or per-user fees: one license covers every system you analyze offline. Optional add-ons such as Did-Do Analysis are priced openly on the pricing page, and a 14-day trial runs on your own exports. For how this compares to connected GRC suites, see the 13 SAP SoD tools comparison.
Frequently asked questions
How do I run SoD analysis without access to the production SAP system?
Export the standard authorization tables (USR02, AGR_USERS, AGR_1251, UST12) from the SAP system, then load them into MTC Skopos on any Windows laptop. The manual export takes 5 to 10 minutes and the analysis of a 10,000-user system completes in under 2 minutes, so you go from extraction to findings in under 15 minutes without any production account, RFC connection, or installed agent.
Is offline SoD analysis as accurate as running a tool inside SAP?
Yes. The exported tables contain the same authorization values SAP evaluates at runtime, and MTC Skopos analyzes them at authorization-object level, including organizational values. The result is identical to what a connected analysis of the same snapshot would produce; the only difference is that findings reflect the extraction date rather than a live view.
What risks are checked in an offline analysis?
MTC Skopos ships with a template ruleset of 350+ SoD risks, 700+ critical access checks, and 100+ authorization quality checks such as organizational value coverage and maintenance activities hiding in display roles. The ruleset is editable down to authorization-object level, and you can import your own or your client's ruleset instead.
Can I get did-do evidence without a production connection?
Yes. Adding transaction usage statistics (ST03N/STAD exports) and change documents (CDHDR/CDPOS) to the extraction lets the Did-Do Analysis add-on show which conflicting access was actually exercised, all still offline.
Does the SAP data get uploaded anywhere during the analysis?
No. MTC Skopos is a portable desktop application with no hosted component and no telemetry. The authorization data stays on the machine running the analysis, which keeps security review of the approach short: there is no cloud processor to assess.
Related reading: SAP Access Risk Analysis · SoD tool for auditors · SoD tool for consultants · Multi-ERP SoD analysis · 13 SAP SoD tools compared