Partner Access with Time Boxes addresses a problem most SAP landscapes know too well: Role spreadsheets expire the day after export; SoD surprises appear at audit.

Role Management explorer, org authorization matrix, authorization groups, and custom scans give auditors evidence — not annual spreadsheet archaeology.

AccessGuard (AG) syncs SAP roles and profiles, catalogs SoD risks, stores RM snapshots, compares scans, and raises compliance alerts when critical authorizations drift.

Capabilities you use in iDataEngine

  • RM explorer and org authorization matrix
  • Authorization groups and critical auths
  • Compliance alert digest mail
  • Partner time-boxed access patterns
  • Risk catalog and SoD rules
  • Custom scan definitions

Recommended workflow

  1. Enable monitoring alerts and review dashboard KPIs for the first production cycle.
  2. Run Test (iDataView Test, SQL First Row, API Test Service, or AG scan) before scheduling or publishing.
  3. Extend the same definition to the next channel (API, SQL, MF, BI) without redesigning from scratch.
  4. Open the relevant cockpit (iDataView Explorer, SQL Project, API Service Detail, or AccessGuard).

Real-world scenario (2024)

Before SOX testing, IT stores an RM snapshot, deploys new AP roles, re-scans, and exports compare — findings attach to the change ticket.

Why it matters

Snapshots turn 'what did roles look like then?' into a answered question — critical for investigations and regulatory reviews.

Innovation here means business sees results faster — IT keeps control because every step is configured, tested, and monitored.