Access risks remain a foundational risk-management problem because weak Separation of Duties (SoD), over-entitlement, and poorly governed access are repeatedly exploited by both internal and external attackers. Traditionally, organizations have treated Access Risk Management (ARM) for major Line of Business (LoB) applications (especially SAP) as separate from broader Identity Governance & Administration (IGA), which covers identity lifecycle management, provisioning, and access governance across many systems. That split is increasingly untenable: IGA is shifting toward AI/ML-driven automation and more dynamic governance, while ARM is expanding beyond single-vendor LoB stacks as enterprises adopt mixed landscapes—such as Salesforce for CRM alongside SAP or Oracle for ERP—and SaaS “satellites” around SAP.
As these trends converge, ARM and IGA integration becomes a logical requirement because SoD controls and access risks span multiple applications, not just core ERP. Core ARM capabilities increasingly include provisioning and lifecycle management for LoB accounts, access requests and fulfillment, certifications, SoD rulebooks enriched with usage data, emergency “firefighter” privilege escalation, risk analytics, and “what-if” access modeling.
SailPoint has expanded into ARM through its acquisition of ERP Maestro and offers SailPoint Access Risk Management as part of the SaaS-based SailPoint Identity Platform. The product emphasizes unified risk management across applications, enterprise-wide visibility for cross-application SoD and simulation before granting access, and compliance/audit via unified reviews and reporting. Dashboards provide configurable, persona-based insights with drill-down. Deep SAP functionality includes out-of-the-box audit-oriented rulebooks, sensitive access reviews, emergency access controls, and contextualized review decisions using usage and simulated risk impact. Strengths include SaaS deployment, REST APIs, AI/ML-enhanced analytics, and SAP depth; challenges include limited non-SAP depth, dependence on broader platform components, and no combined management of Fiori entitlements with SAP S/4HANA and ECC entitlements.
See All Locations
See All Locations