Executive Summary 

In our previous blog post ‘Bridging the Divide: Understanding Cross-System SoD Challenges Between Salesforce and S/4HANA,’ we explored the significant hurdles of managing Segregation of Duties (SoD) across Salesforce and SAP S/4HANA’s disparate security models. Now, we turn our attention to the solution: how specialized access governance platforms like AccessHub provide the essential bridge, enabling comprehensive SoD detection and robust risk management in these complex hybrid environments. 

AccessHub’s Architecture and Role in SoD Enablement 

AccessHub plays a critical role here by acting as a comprehensive gateway that extends SAP Access Governance Solutions to non-SAP environments. It does not perform risk analysis itself but enables it by delivering normalized data that GRC platforms can interpret and evaluate. 

AccessHub achieves this by: 

  • Ingesting and normalizing deep entitlement data from Salesforce and other non-SAP systems: 
  • Ingest: Pulls live entitlements from connected systems. 
  • Normalize: Structures permissions into a unified schema (Resource, Permission, Action, Value). This is crucial for translating disparate models like Salesforce’s layered permissions and SAP’s authorization objects into a common language. 
  • Correlate: Matches user identities across systems, ensuring that a single user’s access across multiple platforms is accurately linked for holistic analysis. 
  • Deliver: Pushes enriched entitlement data into SAP GRC or IAG for SoD evaluation, providing a structured dataset that GRC platforms can interpret and evaluate. 

Implementation Guidance 

Implementing a robust cross-system SoD solution involves a streamlined, three-step process, leveraging AccessHub and SAP GRC capabilities: 

Blog by Accesshub.AI

Step 1: Configure AccessHub 
Set up your endpoints and connect Salesforce applications with just a few clicks. No custom code required. This involves onboarding the Salesforce Connector on AccessHub by clicking “Add New Application,” providing the required details of the Target (Salesforce) Application, and submitting to onboard the application.

Blog by Accesshub.AI
  • Step 2: Integrate with SAP GRC Access Control 
    Establish secure, bi-directional communication between AccessHub and your existing SAP GRC system. This step involves: 
  • Configuring Webservice Connection: Create a WSDL connection for the Salesforce application in GRC AC using Webservice configuration. Provide the required details of the Target (Salesforce) Application and submit to create a logical application connection. 
Blog by AccessHub.AI

Creating Salesforce Connector in GRC AC: Execute the SM59 Transaction to create a Salesforce connector with connection type G. Provide the required details for the connection and test it. This connector will be used for communication between GRC AC and the Salesforce Application via AccessHub. 

Blog by Accesshub.AI
  • Step 3: Execute Repository Sync & Provisioning 
    AccessHub collects user roles and entitlements from connected systems and feeds them into SAP GRC Access Control. You can then perform risk analysis, enforce SoD policies, and automate provisioning across both SAP and non-SAP environments. This includes: 
  • Repository Sync: Select Profile, Role, and User for synchronization. Choose the Salesforce Connector and select “Full Sync Mode.” Additionally, select advanced options like “Sync Future dated Assignment” and “Role Authorization Data,” “Profile Authorization Data.”  
Blog by AccessHub.AI

Repository Sync Successful 

Blog by AccessHub.AI
  • Upon execution, Salesforce Profiles, Roles, and Users are synced to the GRC AC Repository (e.g., visible in tables like GRACRLCONN, GRACUSER, GRACUSERROLE, GRACROLE). Here are Few Key tables data for reference 
  • GRACRLCONN 
Blog by AccessHub.AI

GRACUSER 

Blog by AccessHub.AI
  • Access Request Management (ARM): SAP GRC Access Control (ARM) provides ARM for streamlined access provisioning. Key features include integration capabilities with other SAP and non-SAP systems via AccessHub, self-service access requests, automated multi-level approval workflows, real-time SoD risk analysis and mitigation, comprehensive audit and reporting, and a mobile-friendly Fiori-based UI. 
  • Access Request Submission: Users log in to SAP GRC AC, fill out the Access Request form (including request type, requested for, description, priority, business process, and Salesforce Role details), and submit the request. 
Blog by AccessHub.AI
  • Access Request Approval: Approvers receive the request in their work inbox, review the form, and make a decision to approve or reject. 

Access Request Status: 

Blog by AccessHub.AI

Access Request Approval by Approver: 

Blog by AccessHub.AI

Access Request Provisioning/De-provisioning: Once approved, the access request is submitted for provisioning. Audit logs confirm successful provisioning and role assignment in Salesforce. For de-provisioning, users select existing assignments, choose roles to be removed, and submit the request, which then goes through an approval process, leading to successful de-provisioning and role revocation in Salesforce. 

Blog by AccessHub.AI

Access Risk Analysis (ARA): 
SAP GRC Access Control (ARA) provides proactive risk management by detecting and mitigating Segregation of Duties (SoD) and critical access risks. Key features include real-time risk analysis during access requests, continuous monitoring of user access, cross-application risk analysis across SAP Systems, automated risk remediation, and detailed audit-ready reporting. With AccessHub as a gateway, these capabilities extend seamlessly to non-SAP applications, ensuring enterprise-wide governance and compliance. 

User-Level Risk Analysis for Salesforce via AccessHub Gateway: 

With SAP GRC Access Control 12.0 integrated through AccessHub Gateway, enterprises can perform user-level risk analysis not only for SAP applications but also for Salesforce and other non-SAP systems. This enables organizations to identify Segregation of Duties (SoD) conflicts and critical access risks within Salesforce users—ensuring consistent governance across the hybrid landscape. 

Process Steps 

  1. Navigate to Access Risk Analysis

From the SAP GRC Fiori or NWBC launchpad, go to: 
Access Management → Access Risk Analysis → User Level Risk Analysis 
2. Select Application & User 

  • Application: Salesforce (via AccessHub connector) 
  • User: Enter Salesforce User ID synced into GRC 
Blog by AccessHub.AI
  1. 3. Run Risk Analysis

Execute the risk analysis report to evaluate the selected user’s Salesforce role assignments against the active SoD and critical access ruleset. 

  1. 4. Review Risk Analysis Results

The output will display: 

  • Identified SoD conflicts at Action and Permission Level: 
  • Action Level: 
Blog by AccessHub.AI

Permission Level: 

Blog by AccessHub.AI

Critical access risks: 

Blog by AcccessHub.AI

Critical Permission Risk 

Blog by AccessHub.AI

Cross-Application Risk Analysis 

SAP GRC AC can also perform cross-application risk checks where Salesforce access is analyzed together with SAP S/4HANA or other connected applications. Follow Process step 1 to 3 as above by selecting a user having access across SAP S/4HANA and SALESFORCE Application. 

Review Risk Analysis Results 

The output will display: 

  • Identified SoD conflicts at Action and Permission Level: 
  • Cross Application Action Level Risk: 
Blog by AccessHub.AI

Cross Application Permission Level Risk: 

Blog by AccessHub.AI

Key Benefits 

  • Unified user-level risk visibility across SAP & Non-SAP systems 
  • Automated and real-time SoD checks at the time of access requests 
  • Cross-application risk detection to ensure holistic governance 
  • Seamless Salesforce integration using AccessHub as gateway 

Conclusion  

Managing Segregation of Duties in modern, hybrid IT environments is a complex but critical endeavor. While Salesforce offers granular controls, its inherent complexity, combined with the disparate authorization models of systems like SAP S/4HANA, creates significant challenges for SoD. Manual approaches are no longer viable given the exponential growth of “toxic combinations.” 

Automated solutions like AccessHub are indispensable. By ingesting, normalizing, and correlating deep entitlement data from Salesforce and other non-SAP systems, AccessHub provides the high-resolution access data that SAP GRC needs to perform comprehensive cross-system SoD analysis. This enables organizations to proactively identify and mitigate risks, ensure compliance, and protect against fraud and errors. 

This three-part series has taken us on a journey from understanding individual security models to identifying complex cross-system SoD challenges, and finally, to exploring how innovative solutions like AccessHub provide the critical capabilities for effective governance. By integrating Salesforce with SAP GRC through normalized data, organizations can achieve true end-to-end access visibility and proactive risk mitigation. 

Don’t let cross-system complexities compromise your security posture. Take the next step: 

Ready to implement a robust cross-system SoD solution for your enterprise? Contact us today to learn how AccessHub can empower your access governance strategy. 

Start Here

One Platform. Total Control. Smarter Access

Thank you! We'll get back to you soon!