AuditDesk

Automated SAP security and compliance audit

Continuous, evidence-based SAP access and control monitoring — without a manual export cycle.

Extract, score, report, repeat

Extract

RFC, read-only, straight from your SAP tables.

Score

Every metric checked against your own documented policy.

Report + brief

A detailed audit report and an executive briefing, from the same data.

Repeat

Runs again on schedule, so the picture never goes stale.

SAP access risk is hard to see until it's audited

The problem AuditDesk was built to close.

Manual, point-in-time

SoD conflicts, debug access, and privileged profiles are typically reviewed on a quarterly export — risk accumulates silently in between.

Spreadsheet-dependent

Findings live in ad hoc spreadsheets with no consistent scoring, making trend tracking and audit evidence collection slow and error-prone.

Inconsistent judgment calls

Without a documented, versioned risk policy, two reviewers can score the same finding differently — a problem in any audit trail.

Reporting is a separate project

Turning raw SAP tables into something a CISO or auditor can actually read is its own manual effort, every single cycle.

Five control domains, tracked continuously

01 · segregation of duties

Combined authorizations that bypass independent review — develop+unlock, config+unlock, table-modify+unlock, transport conflicts.

02 · access management

Privileged profiles (SAP_ALL/SAP_NEW), debug access, and elevated backend/Fiori footprint.

03 · passwords

Standard account (SAP*/DDIC) hardening status across every client, and custom policy deviations.

04 · logging

Client lock status, audit log continuity, key table logging, and SAP* recreation controls.

05 · change management

User type changes, and whether each one carries a documented business reason.

Built for audit integrity, not just automation

  • Read-only, always. The extraction user only needs standard read authorizations. Nothing in the pipeline writes to SAP.
  • Your policy, not ours. RAG thresholds live in a workbook your team owns and edits — Green/Amber boundaries and rationale, version-controlled like any other policy document.
  • Honest about gaps. Fields that aren't reliably available via standard RFC reads are marked "Unknown — verify manually" rather than guessed.
  • One source, two audiences. The detailed report and the executive briefing are generated from the identical scored dataset — leadership and auditors never see different numbers.

Two outputs, generated from the same scored data

for the audit trail

Detailed report — Word / PDF

Full findings by domain, RAG-scored against policy, supporting record drill-downs (who, what, when), and a methodology appendix.

for the CISO / IT head

Executive briefing — PowerPoint

Overall status, risk heatmap by domain, top findings, and 90-day priorities — built for a 10-minute leadership conversation.

From pilot to standing capability

Configure

Set connection details, confirm read-only authorizations, and document your RAG thresholds and rationale.

Pilot

Run against one production client. Validate findings against what your team already knows to be true.

Automate

Schedule unattended runs and route outputs to the audit team and leadership distribution.

Extend

Add systems and clients, refine thresholds, and fold findings into the standing risk register.

What we need to get started

A read-only RFC service account

Standard read authorizations only — S_TABU_DIS, S_RFC per function module, optionally S_XPGL for audit log reads. No write access, ever.

Your risk thresholds, documented

Even a first draft of Green/Amber boundaries per metric — this becomes yours to refine over time.

One pilot system, and a distribution list

A single client to validate against, and clarity on who receives the detailed report versus the executive briefing.

Let's put this on a schedule

Get started