Organizations rely on Line of Business (LoB) applications for core operations across finance, supplier management, CRM, and HR. Although SAP remains dominant, most enterprises operate heterogeneous environments that combine SAP with other large suites, specialist products, and rapidly growing SaaS services. SaaS adoption and SAP’s own acquisition of SaaS products—often with architectures and security models different from SAP ECC and S/4HANA—are reshaping access control and governance requirements. Because LoB applications underpin critical processes and regulated data, organizations need strong capabilities for access management, Segregation of Duties (SoD) enforcement, and emergency access control.
The challenge is balancing depth (understanding complex entitlement models such as SAP business roles, single roles, authorization objects, transactions, and Fiori entitlements) with breadth (covering many LoB and adjacent services like file storage and office suites). SoD analysis must work within single applications and across end-to-end, cross-application processes, while enabling maintainable rulesets that can adapt to business change and harmonize configuration differences across instances. This drives convergence between SAP-focused access control/GRC and broader IGA, since lifecycle management, provisioning, and governance increasingly span mixed application portfolios.
Pathlock—originating as Greenlight Technologies and expanded via acquisitions of Appsian, Security Weaver, CSI Tools, and SAST Solutions (2022)—offers a SaaS-based Pathlock Platform (and separate on-premises offerings) focused on protecting business applications, data, and processes. The platform supports 140+ applications, provides unified connectors, a consistent UI, a risk dashboard with KRIs and historical comparisons, and 90+ out-of-the-box reports. Core capabilities include fine-grained cross-system SoD, provisioning with simulation and mitigations, continuous entitlement usage monitoring (“can do”), transaction monitoring (“did do”), role analytics, emergency access management, recertification automation, workflows, and controls libraries/playbooks aligned to major compliance frameworks. Strengths center on breadth across LoB apps and cross-system analytics; current challenges include only baseline process controls (mainly financial) and SaaS fit constraints for some customers.
See All Locations
See All Locations