These reports will be updates of the previously published Leadership Compasses on Access Control Tools for SAP Environments in 2023 and Access Control Tools for Multi-vendor LoB Environments in 2023.
With this edition of the Leadership Compass, we are introducing a significant change in how we segment and evaluate the market: the former analysis of access control and governance in SAP and other business applications, one with focus on SAP only, the other with focus on multi-vendor LoB (Line of Business Applications) focus, is now transitioned into two separate, more focused Leadership Compass reports. This decision reflects both the growing divergence in customer needs and the increasing specialization of vendor offerings. The first report, SAP Access Control and Security, now expands its scope beyond traditional access governance and Segregation of Duties (SoD) controls to include a strong emphasis on SAP Security — encompassing areas such as threat detection, system hardening, privileged access management, and audit support. This shift acknowledges that securing SAP environments today requires more than entitlement governance; it demands integrated security capabilities that are deeply embedded in the SAP landscape.
The second report, Access and SoD Control for LoB Applications (including SAP), focuses exclusively on access control and SoD governance, but across a broad spectrum of business-critical applications, not limited to SAP. These include platforms such as Salesforce, Workday, Oracle eBusiness Suite, and Microsoft Dynamics, among others. While SAP support is still in scope for this LC, it is treated as one among several LoB systems, and depth in SAP-specific security features is not required at the same level as for the first of the two LCs. Instead, the emphasis is on the ability to manage entitlements and enforce SoD policies consistently across heterogeneous and often cloud-centric enterprise application environments. This separation allows for clearer market positioning by vendors and provides buyers with more targeted insights into the solutions that best meet their specific architectural and compliance needs.