TL;DR: Traditional access management answers who can act, but ERP and business-critical environments increasingly need proof that each transaction was appropriate, continuous, and compliant, according to Pathlock’s webinar on Nexus. The governance gap is shifting from access certification to transaction-level assurance, especially where AI widens compliance blind spots.
Editorial analysis by NHI Mgmt Group, based on content published by Pathlock: “From Certified Access to Certified Transaction: How Pathlock Nexus Changes the Game.”.
Key questions
Q: What breaks when access certifications are handled manually in complex ERP environments?
A: Manual certification processes tend to miss stale entitlements, overload reviewers, and slow remediation, especially when users span multiple systems and business units.
Q: Why do ERP transactions need continuous assurance instead of periodic review?
A: ERP transactions often occur inside legitimate sessions, so the risky event is the action itself, not just the login.
Practitioner guidance
- Define transaction assurance as a control objective Treat business execution evidence as a governance requirement, not as an audit afterthought.
- Map governance checkpoints to runtime events Identify where access certification currently stops and where transaction evaluation should begin inside ERP workflows.
- Prioritise high-risk ERP transactions Start with actions that have financial, compliance, or segregation-of-duties impact, because those are the transactions where continuous assurance will produce the most defensible control value.
Bottom line: ERP governance is moving from who has access to whether each transaction was appropriate at the moment it occurred.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Transaction-level assurance is becoming the real control boundary for ERP governance. Access approval tells you who may enter the system, but not whether a particular business action was justified. That distinction matters in ERP because compliance failures often occur inside legitimate sessions, not at login. The implication is that IAM and IGA programmes have to treat execution as a governed event, not just a granted entitlement.
A question worth separating out:
A: Security and compliance teams should use AI to automate repetitive tasks such as data collection, audit documentation, and regulatory tracking, while keeping control design, approvals, and exception handling under human oversight. The goal is faster response and better consistency, not blind automation. AI should strengthen traceability, reduce manual error, and help teams keep controls aligned with changing requirements.
👉 Read our full editorial: Continuous transaction governance for ERP identity control