See All Locations
Unlike traditional risk, audit, and security systems, Pathlock continuously monitors transactions across all enterprise applications where sensitive activities and data are concentrated. It surfaces actual violations, not theoretical possibilities. With Pathlock as the hub, all lines of defense work together to make informed decisions.
Founded as Greenlight Technologies, we became the only solution endorsed by SAP that extends SAP Access Control to cloud and non-SAP systems.
In May of 2022 we announced the strategic acquistion and mergers of Pathlock with Appsian, Security Weaver, CSI Tools, and SAST-Solutions to deliver a vision of a complete 360-degree platform for the protection of critical business applications, data, and processes.
Today, we are the leader in application security and controls automation, serving customers worldwide.
Access recertification is one of the most unpopular and resource-intensive processes in Identity Governance and Administration. Managers are often confronted with massive matrices of users and entitlements they barely understand. The result is review fatigue, rubber-stamping, and a compliance exercise that rarely reduces real risk or improves access quality.
Modern identity governance technologies enable a fundamentally different approach. By enriching access reviews with business context, usage insights, and segregation-of-duties risk visibility, organizations can prioritize what truly matters. Automation, event-driven workflows, and continuous governance models allow companies to shift from periodic certification campaigns to dynamic, risk-aware access validation.
Martin Kuppinger, Principal Analyst & Co-Founder at KuppingerCole will examine why traditional recertification approaches fail and why incremental improvements have not solved the root problem. They will explore tactical measures such as simplifying access models, leveraging policy-based assignments, and using usage insights, while also outlining the strategic shift toward policy-driven and continuous access governance.
Damon Tompkins, Chief Executive Officer at Pathlock will discuss how organizations can operationalize these principles across complex enterprise systems such as ERP environments. They will demonstrate how risk-aware certifications, enriched with usage and segregation-of-duties insights, event-driven review triggers, and workflow automation can significantly reduce certification workloads while strengthening compliance and governance.
IGA teams face a widening gap between what their tools were built for and what their environments demand. Access changes constantly, access reviewers are drowning in information, risk spans hybrid ERP and SaaS systems, and compliance now requires continuous assurance. At the same time, AI promises to simplify decisions, but without business context, it creates more noise than value.
Modern IGA platforms now combine cross-application correlation, continuous controls, and context-rich intelligence to overcome these limitations. When AI is enriched with process, policy, and risk metadata, it can guide access decisions, accelerate reviews, and eliminate blind spots across SAP, Oracle, Workday, PeopleSoft, and SaaS environments. This shifts IGA from reactive administration to real-time, proactive governance.
Patrick Teichmann, Lead Advisor at KuppingerCole, will outline why traditional IGA approaches are no longer sufficient, describe emerging IAM trends, and explain the concept of context-engineered identity intelligence. He will highlight the five core capabilities legacy tools cannot deliver and why they should matter to organizations.
Gerald West, Founder of CaroKahn and Principal Advisor, will share practical insights from decades of SAP and ERP security leadership. He will demonstrate how continuous controls reduce audit workload, how AI-guided decisions prevent over-entitlement, and how cross-application correlation eliminates hidden SoD risks. Gerald will also illustrate real examples from ERP-centric organizations modernizing their governance model.
SAP is the beating heart of many enterprises, but risky ABAP code, unmanaged transports, and poor compliance visibility can stop it cold. Manual reviews are too slow, threats move too fast, and audits demand too much. It’s time for a shift from reactive fixes to continuous, automated SAP governance.
Modern application governance tools can automatically identify and block risky changes before deployment, enforce granular transport controls, and provide real-time monitoring. By combining intelligent policy enforcement with delegated control, these solutions give IT and compliance teams full visibility while streamlining audit readiness. The result is a secure, Zero Trust SAP environment that operates efficiently and stays continuously compliant.
Martin Kuppinger, Principal Analyst & Co-Founder at KuppingerCole will explore current industry trends shaping SAP security and compliance, including the shift from static to real-time governance, the role of Zero Trust at the application layer, and the growing importance of automation in meeting audit and regulatory demands. They will provide a market perspective on best practices and common pitfalls in SAP change management.
Clemens Guetter, SAP Architect at Pathlock will demonstrate how Pathlock’s Application Profiler for SAP secures custom code and change management. He will show how to detect and block risky ABAP code before deployment, enforce transport controls, and provide compliance teams with full application-level visibility. Clemens will highlight real-world use cases where Pathlock has enabled continuous compliance and streamlined audit readiness without disrupting operations.
In SAP environments, the separation of compliance and application security creates critical blind spots that expose organizations to risks. Misconfigurations can lead to both regulatory non-compliance and security vulnerabilities, jeopardizing business-critical data. Traditional approaches often fail to proactively identify and mitigate these risks, resulting in audit failures, data breaches, and operational inefficiencies.
To address these challenges, organizations must adopt a holistic governance model where security enables compliance rather than hindering it. By applying CIANA+PS principles—Confidentiality, Integrity, Availability, Non-repudiation, Authentication, Privacy, and Safety—teams can align technical SAP settings with compliance requirements. Leveraging automation tools ensures continuous monitoring, proactive remediation, and streamlined audit preparation.
Martin Kuppinger, Founder and Principal Analyst at KuppingerCole, will discuss the philosophical connection between compliance and application security in SAP environments. He will highlight the risks of treating them as separate disciplines and provide insights into how integrated governance models improve enterprise resilience. Martin will also share real-world examples of misconfigurations that impact both security and compliance.
Jonathan Stross, SAP Security Analyst & Consultant at Pathlock, will showcase practical strategies for identifying and mitigating SAP misconfigurations using advanced tools like Pathlock Cloud. He will demonstrate how automation can reduce manual effort while ensuring continuous compliance monitoring. Jonathan will also present actionable steps for building a unified governance model that balances security priorities with regulatory requirements.
The impending end-of-life for SAP Identity Management (IDM) presents a critical juncture for organizations relying on this solution. As support winds down by 2027, with extended maintenance until 2030, businesses face urgent challenges in maintaining robust identity and access management frameworks. This transition period offers a unique opportunity to modernize and unify identity security and governance strategies.
Pathlock's Application Access Governance (AAG) solution emerges as a comprehensive answer to these challenges. As both a Microsoft Entra ID partner and AAG provider, Pathlock offers a seamless path for organizations to govern identities across SAP and non-SAP applications. This unified approach not only addresses immediate security and compliance needs but also future-proofs organizations against evolving regulatory requirements and application landscapes.
Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will examine the situation SAP customers face with the end-of-life of SAP IdM and changes around SAP (GRC) Access Control. He will provide insights on proactive steps customers should take, emphasizing the importance of preparing for the future with IGA solutions designed for long-term viability.
Keri Bowman, Senior Director of Product Marketing at Pathlock, will demonstrate how Pathlock's AAG can address the challenges faced by organizations in the post-SAP IDM era. They will showcase how AAG enables a seamless transition from SAP IDM, offering enhanced capabilities in SoD risk analysis, automated access provisioning, and sensitive access management. Pathlock Speaker Name will highlight AAG's role in achieving a Zero Risk approach through unified identity and access risk governance and drive time and cost savings with a singular platform.
In the post-COVID era, higher education institutions face unprecedented challenges in managing student matriculation and access governance. With IT departments stretched thin and an influx of in-person students, the risk of over-provisioning and compliance violations has skyrocketed. Balancing efficiency with data security and privacy concerns with FERPA, HIPAA, and other regulations has become a critical issue for HigherEd CIOs and IT professionals.
Modern technology offers a solution through automation of student enrollment processes and access reviews. By implementing "touchless" matriculation systems and streamlined user access controls, institutions can significantly reduce the burden on IT resources while enhancing security and compliance. This approach allows for efficient management of student identities across multiple systems, from initial enrollment to graduation or departure.
Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will discuss why student identity management presents an "IAM on steroids" challenge. He will explore how the high turnover of student identities surpasses typical workforce IAM issues, and explain why integrating IAM, GRC, and Line of Business systems is crucial for addressing these unique challenges in higher education.
Greg Wendt, Executive Director Security Solutions at Pathlock, will present practical strategies for achieving automated student matriculation and streamlined access reviews. He will demonstrate how Pathlock's solutions can help higher education institutions reduce security and compliance risks, alleviate IT burdens, and optimize operations in the face of evolving educational landscapes.
Hi, I'm Piyush Pandey, the CEO of Pathlock. We've been a client of KuppingerCole for over three years now and over this time period, they've been instrumental in shaping our strategy as we navigate our path through broader identity governance and security market. The insights provided by Martin Kuppinger and his team have been instrumental in providing us clarity as well as a thoughtful approach to deconstruct the market and apply our capabilities in broader market as well as to specific customers. We look forward to continue our collaboration with KuppingerCole and continue to leverage their expertise as we navigate our journey in the identity space.
In this webinar, you will learn about
Keri Bowman, Sr. Director Product Marketing at Pathlock, and Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will talk about a range of aspects concerning the state and future of IGA and LoB Application Access Management.
In this webinar, you’ll learn about
Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will look at the state of the market, the requirements on solutions, and will present selected results from the recent KuppingerCole Leadership Compasses covering this market segment for both SAP-specific and multi-vendor LoB environments.
Keri Bowman, Sr. Director Product Marketing, at Pathlock, then will explain how the Pathlock solutions support customers in managing access controls, access risk, and SoD rules across multiple LoB applications from different vendors from a unified interface.
Join security experts from KuppingerCole Analysts and Pathlock as they discuss why modern applications need more granular and context-based access controls, why it is important that these controls can adapt to changing business needs and user behaviors, and how that can be achieved.
Martin Kuppinger, Principal Analyst at KuppingerCole Analysts, will provide a head-to-head comparison of key features of common, traditional IGA, and the established access control tools for SAP and other Line of Business (LoB) applications.
Carrie Curry, VP of Customer Advisory at Pathlock will explain the benefits of a holistic application access management approach that can provide real-time access decisions based on contextual data, that can support compliance, that provides fine-grained controls, and that can reduce the cost and effort of access reviews. She will also discuss why organisations need to have a cross-system and application view when it comes to Access Governance.