Skip to content
Coverage

Connectors for the systems your controls run on

Access risk does not stop at the edge of an ERP. One person can hold a purchasing role in one system, an approval limit in a second and a directory group in a third — and it is the combination that creates exposure.

Governing each application on its own cannot see it.

One policy engine evaluates eight connected systems together: Oracle ERP Cloud, SAP S/4HANA, Workday, Coupa, Microsoft Entra ID, Salesforce, Kyriba and ServiceNow. · Privileges that are unremarkable on their own become conflicts once the systems are read as one estate — creating a supplier in one system and approving its invoices in another, posting a journal in one and releasing the payment in another, maintaining a vendor record in one and changing its bank details in another, or raising a purchase order in one and receipting the goods in another. · None of those combinations is visible to a system governed on its own. · An access matrix of people against eight connected systems, with the cross-system privilege combinations highlighted as conflicts

Illustrative — example cross-system access combinations, not customer data

Why one connector layer

Evaluated once across the estate, not repeated per system.

Every connector feeds the same policy engine and the same evidence trail, so segregation of duties, access certification, provisioning and monitoring are assessed against one picture of who can do what.

Coverage spans

ERPHuman capitalProcurement
TreasuryCRMIdentity providers
Security tooling
Coverage

The applications we connect to.

Many have a dedicated page; the rest are governed with the same controls and documented on request.

Oracle

Segregation of duties, access certification and transaction monitoring across the Oracle estate — the same controls whether a business runs E-Business Suite, ERP Cloud, or both through a migration.

SAP

Role and authorisation analysis for SAP, extended to the procurement, human capital and commerce applications where the same identities carry different privileges.

SAP ECC and S/4HANA Learn more → SAP Ariba Learn more →
SAP SuccessFactors Governed with the same controls · documented on request
SAP Concur Governed with the same controls · documented on request
SAP Commerce Cloud Governed with the same controls · documented on request

Microsoft

Governance across the Microsoft business and identity stack, so a directory group and an ERP role are evaluated as one access position rather than two unrelated ones.

Business applications

The systems that hold real financial and operational risk outside the ERP — treasury, procurement, CRM, asset and portfolio management.

Identity and security

Identity providers, IGA platforms and security tooling, so evidence gathered for governance and evidence gathered for security describe the same estate.

IGA platform SailPoint Learn more → Service management ServiceNow Learn more →
Identity provider Okta Governed with the same controls · documented on request
Security tooling Splunk Governed with the same controls · documented on request
Security tooling CrowdStrike Governed with the same controls · documented on request
Security tooling Palo Alto Governed with the same controls · documented on request
Security tooling Zscaler Governed with the same controls · documented on request
Not on the list

Most systems with an API or a database can be governed.

Coverage is extended regularly, and a system that exposes its users, roles and privileges can usually be brought under the same controls as the rest of the estate. Tell us what you run and we will confirm what is possible today.

Talk to a Governance Expert