Enterprises should move from role only reviews to activity based controls that correlate what users actually do with what they are allowed to do. The goal is to surface real risk across SAP and connected systems, automate evidence collection, and produce audit ready reviews without relying on spreadsheets or periodic manual sampling.
Why This Matters for Security Teams
segregation of duties reviews fail when they are treated as a quarterly checkbox instead of a continuous control problem. In SAP estates, risk rarely sits in a single role. It emerges when a user, service account, integration user, or privileged workflow can combine actions across ERP, procurement, finance, and adjacent applications. That is why activity-based review is more effective than role-only attestation, especially where NIST SP 800-53 Rev 5 Security and Privacy Controls emphasizes accountable control operation and evidence. NHIMG’s Ultimate Guide to NHIs — Why NHI Security Matters Now underscores why this matters: only 5.7% of organisations have full visibility into their service accounts, and 97% of NHIs carry excessive privileges. The practical risk is that connected business applications extend SAP access paths beyond the original role catalog. A reviewer can approve a clean-looking role while missing toxic combinations that appear only when transaction logs, workflow traces, API calls, and delegated access are correlated. In practice, many security teams discover SoD exposure only after audit exceptions, fraud reviews, or a production incident have already exposed the gap.How It Works in Practice
Effective automation starts by joining identity, entitlement, and activity data into a single review pipeline. SAP roles and authorizations should be mapped to business functions, then correlated with actual execution evidence from SAP audit logs, middleware, GRC tools, workflow platforms, and connected applications. The goal is to identify what a person or service can do, what they actually did, and whether any combination creates an SoD conflict that matters to the business. A workable operating model usually includes:- Role and entitlement inventory across SAP and downstream systems, refreshed continuously.
- Activity ingestion from SAP transactions, approval events, API calls, and privileged sessions.
- Policy rules that flag toxic combinations, compensating controls, and exceptions with expiration dates.
- Reviewer workflows that route only material exceptions, not every entitlement line item.
- Evidence capture that preserves who approved, what was reviewed, and what logs supported the decision.
Common Variations and Edge Cases
Tighter SoD automation often increases data integration and governance overhead, so organisations have to balance review precision against system complexity and reviewer fatigue. That tradeoff is especially sharp in mixed SAP environments, where cloud applications, custom ABAP logic, robotic process automation, and shared service accounts all create different evidence formats. Best practice is evolving in three areas. First, some teams review only human users at first, then extend the same logic to service and integration accounts once they can reliably trace machine activity. Second, compensating controls are sometimes accepted for unavoidable conflicts, but only when they are time bound, logged, and independently validated. Third, there is no universal standard for how much telemetry is enough for an audit-ready SoD review, so policy teams should define minimum evidence thresholds rather than rely on vendor defaults. NHIMG’s SAP SQL Anywhere Monitor Hardcoded Credentials case shows why connected applications matter: SoD risk can be undermined by credentials and access paths that bypass the review process entirely. The most effective programs therefore treat entitlement review, credential governance, and activity monitoring as one control chain, not separate projects. Enterprises that split these functions often end up with clean certifications and unresolved operational risk.Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10, OWASP Agentic AI Top 10 and CSA MAESTRO address the attack and risk surface, while NIST CSF 2.0 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-03 | SoD reviews fail when long-lived credentials and overprivilege are not governed. |
| OWASP Agentic AI Top 10 | Automated reviews depend on trustworthy machine actions and constrained execution paths. | |
| CSA MAESTRO | Connected business apps need runtime policy checks across tool use and delegated actions. | |
| NIST CSF 2.0 | PR.AC-4 | Least-privilege and access review controls underpin SoD governance across systems. |
| NIST AI RMF | Automated SoD reviews need governance, traceability, and risk-based oversight. |
Treat autonomous workflows as high-risk actors and constrain their approvals, tools, and escalation paths.
Related resources from NHI Mgmt Group
- Why does separation of duties become harder to enforce across connected business systems?
- How should security teams implement segregation of duties across multiple business applications?
- How should security teams automate internal controls in business applications to improve trust in reporting?
- Why do SAP and ERP environments require tighter governance than standard business applications?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org