Join our Newsletter — 33% off our NHI Course

Organisational Value

An organisational value is a field-level scope attribute that changes what a SAP role can act on, such as company code or plant. These values can quietly widen or narrow effective access, so SoD analysis must evaluate the assigned value, not just the role name.

How Organisational Value Changes Role Scope

An organisational value is not a permission by itself. It is the scoped field that tells the system where a role is allowed to operate, so the same role can behave differently across company codes, plants, or other organisational units.

This matters because the role name can look unchanged while the effective access is materially different. A narrow value can constrain activity to a small business slice, while a broad value can extend the same transaction rights across a much larger part of the enterprise.

Why It Matters for Segregation of Duties

Segregation of duties analysis has to evaluate the assigned value, not just the abstract role template. A role that is acceptable in one organisational context may become excessive, conflicting, or business-critical when the organisational value changes what records, postings, or approvals it can touch.

That is why organisational values often decide whether a role assignment is operationally safe. In practice, access reviews and SoD checks need to treat scope as part of the entitlement, because scope determines the real boundary of authority.

Common Failure Modes

The most common mistake is to review only the role catalog and ignore the value assignment. That creates blind spots where users appear to hold a standard role, but the value attached to it quietly expands access across plants, regions, or company codes.

Another failure mode is inconsistent value governance. If different teams assign different values to the same role without a clear policy, the organisation can end up with uneven control strength, hidden privilege growth, and difficult-to-explain audit outcomes.

How to Assess It Correctly

Review the role and the organisational value as a single access decision. The meaningful question is not only “what role is this?” but also “what scope does this value give the role in practice?”

That evaluation should be done against the business object the role controls, such as finance postings, plant operations, or location-specific actions. When the value changes the reachable business scope, it changes the security meaning of the role.

Risk and Threat Considerations

Organisational values can create hidden privilege expansion when a role is reused across wider scopes than intended. That turns a seemingly routine assignment into a concentration of business authority, especially where SoD conflicts only emerge at the value level.

Failure mechanism: Reviewers approve the role pattern but miss the scope encoded in the organisational value, so access can be extended across additional company codes, plants, or comparable business units without being recognised as excessive.

Impact: The result can be unauthorized postings, approvals, or master-data changes across a broader operating footprint, plus weaker auditability and higher SoD exception risk.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.

Framework Control / Reference Relevance
NIST SP 800-53 Rev 5 AC-6 — Least Privilege Organisational values change the effective scope of access and privilege.
AC-2 — Account Management Role assignments with organisational values are part of account provisioning and review.
Recommendation — Review value-scoped access to ensure each assignment stays within least-privilege bounds. Include organisational values in account reviews so scoped entitlements are validated, recertified, and removed when unnecessary.
ISO/IEC 27001:2022 A.5.15 — Access control Scope attributes directly affect who can access which business resources.
A.5.18 — Access rights Organisational values alter the actual access rights granted by a role.
Recommendation — Define and enforce role-scope rules so organisational values cannot widen access beyond policy. Review access rights at the value level, not just the role label, during periodic recertification.
CIS Controls v8 CIS-5 — Account Management Scoped role assignments are an account-management control issue.
Recommendation — Inventory scoped role assignments and remove value combinations that create excess access.

Practitioner Guidance

What to watch for: Treat organisational value changes as entitlement changes, not cosmetic metadata. If a role is reused in multiple scopes, validate whether each value still matches the intended business boundary and whether the resulting access remains SoD-clean.

Governance implication: Keep ownership of role design and value assignment explicit. The role template defines the pattern, but the value defines the real operating scope, so both need review during access provisioning and periodic recertification.