Executive Summary
In our previous blog post ‘Bridging the Divide: Understanding Cross-System SoD Challenges Between Salesforce and S/4HANA,’ we explored the significant hurdles of managing Segregation of Duties (SoD) across Salesforce and SAP S/4HANA’s disparate security models. Now, we turn our attention to the solution: how specialized access governance platforms like AccessHub provide the essential bridge, enabling comprehensive SoD detection and robust risk management in these complex hybrid environments.
AccessHub’s Architecture and Role in SoD Enablement
AccessHub plays a critical role here by acting as a comprehensive gateway that extends SAP Access Governance Solutions to non-SAP environments. It does not perform risk analysis itself but enables it by delivering normalized data that GRC platforms can interpret and evaluate.
AccessHub achieves this by:
- Ingesting and normalizing deep entitlement data from Salesforce and other non-SAP systems:
- Ingest: Pulls live entitlements from connected systems.
- Normalize: Structures permissions into a unified schema (Resource, Permission, Action, Value). This is crucial for translating disparate models like Salesforce’s layered permissions and SAP’s authorization objects into a common language.
- Correlate: Matches user identities across systems, ensuring that a single user’s access across multiple platforms is accurately linked for holistic analysis.
- Deliver: Pushes enriched entitlement data into SAP GRC or IAG for SoD evaluation, providing a structured dataset that GRC platforms can interpret and evaluate.
Implementation Guidance
Implementing a robust cross-system SoD solution involves a streamlined, three-step process, leveraging AccessHub and SAP GRC capabilities:

Step 1: Configure AccessHub
Set up your endpoints and connect Salesforce applications with just a few clicks. No custom code required. This involves onboarding the Salesforce Connector on AccessHub by clicking “Add New Application,” providing the required details of the Target (Salesforce) Application, and submitting to onboard the application.

- Step 2: Integrate with SAP GRC Access Control
Establish secure, bi-directional communication between AccessHub and your existing SAP GRC system. This step involves:
- Configuring Webservice Connection: Create a WSDL connection for the Salesforce application in GRC AC using Webservice configuration. Provide the required details of the Target (Salesforce) Application and submit to create a logical application connection.

Creating Salesforce Connector in GRC AC: Execute the SM59 Transaction to create a Salesforce connector with connection type G. Provide the required details for the connection and test it. This connector will be used for communication between GRC AC and the Salesforce Application via AccessHub.

- Step 3: Execute Repository Sync & Provisioning
AccessHub collects user roles and entitlements from connected systems and feeds them into SAP GRC Access Control. You can then perform risk analysis, enforce SoD policies, and automate provisioning across both SAP and non-SAP environments. This includes:
- Repository Sync: Select Profile, Role, and User for synchronization. Choose the Salesforce Connector and select “Full Sync Mode.” Additionally, select advanced options like “Sync Future dated Assignment” and “Role Authorization Data,” “Profile Authorization Data.”

Repository Sync Successful

- Upon execution, Salesforce Profiles, Roles, and Users are synced to the GRC AC Repository (e.g., visible in tables like GRACRLCONN, GRACUSER, GRACUSERROLE, GRACROLE). Here are Few Key tables data for reference
- GRACRLCONN

GRACUSER

- Access Request Management (ARM): SAP GRC Access Control (ARM) provides ARM for streamlined access provisioning. Key features include integration capabilities with other SAP and non-SAP systems via AccessHub, self-service access requests, automated multi-level approval workflows, real-time SoD risk analysis and mitigation, comprehensive audit and reporting, and a mobile-friendly Fiori-based UI.
- Access Request Submission: Users log in to SAP GRC AC, fill out the Access Request form (including request type, requested for, description, priority, business process, and Salesforce Role details), and submit the request.

- Access Request Approval: Approvers receive the request in their work inbox, review the form, and make a decision to approve or reject.
Access Request Status:

Access Request Approval by Approver:

Access Request Provisioning/De-provisioning: Once approved, the access request is submitted for provisioning. Audit logs confirm successful provisioning and role assignment in Salesforce. For de-provisioning, users select existing assignments, choose roles to be removed, and submit the request, which then goes through an approval process, leading to successful de-provisioning and role revocation in Salesforce.

Access Risk Analysis (ARA):
SAP GRC Access Control (ARA) provides proactive risk management by detecting and mitigating Segregation of Duties (SoD) and critical access risks. Key features include real-time risk analysis during access requests, continuous monitoring of user access, cross-application risk analysis across SAP Systems, automated risk remediation, and detailed audit-ready reporting. With AccessHub as a gateway, these capabilities extend seamlessly to non-SAP applications, ensuring enterprise-wide governance and compliance.
User-Level Risk Analysis for Salesforce via AccessHub Gateway:
With SAP GRC Access Control 12.0 integrated through AccessHub Gateway, enterprises can perform user-level risk analysis not only for SAP applications but also for Salesforce and other non-SAP systems. This enables organizations to identify Segregation of Duties (SoD) conflicts and critical access risks within Salesforce users—ensuring consistent governance across the hybrid landscape.
Process Steps
- Navigate to Access Risk Analysis
From the SAP GRC Fiori or NWBC launchpad, go to:
Access Management → Access Risk Analysis → User Level Risk Analysis
2. Select Application & User
- Application: Salesforce (via AccessHub connector)
- User: Enter Salesforce User ID synced into GRC

- 3. Run Risk Analysis
Execute the risk analysis report to evaluate the selected user’s Salesforce role assignments against the active SoD and critical access ruleset.
- 4. Review Risk Analysis Results
The output will display:
- Identified SoD conflicts at Action and Permission Level:
- Action Level:

Permission Level:

Critical access risks:

Critical Permission Risk

Cross-Application Risk Analysis
SAP GRC AC can also perform cross-application risk checks where Salesforce access is analyzed together with SAP S/4HANA or other connected applications. Follow Process step 1 to 3 as above by selecting a user having access across SAP S/4HANA and SALESFORCE Application.
Review Risk Analysis Results
The output will display:
- Identified SoD conflicts at Action and Permission Level:
- Cross Application Action Level Risk:

Cross Application Permission Level Risk:

Key Benefits
- Unified user-level risk visibility across SAP & Non-SAP systems
- Automated and real-time SoD checks at the time of access requests
- Cross-application risk detection to ensure holistic governance
- Seamless Salesforce integration using AccessHub as gateway
Conclusion
Managing Segregation of Duties in modern, hybrid IT environments is a complex but critical endeavor. While Salesforce offers granular controls, its inherent complexity, combined with the disparate authorization models of systems like SAP S/4HANA, creates significant challenges for SoD. Manual approaches are no longer viable given the exponential growth of “toxic combinations.”
Automated solutions like AccessHub are indispensable. By ingesting, normalizing, and correlating deep entitlement data from Salesforce and other non-SAP systems, AccessHub provides the high-resolution access data that SAP GRC needs to perform comprehensive cross-system SoD analysis. This enables organizations to proactively identify and mitigate risks, ensure compliance, and protect against fraud and errors.
This three-part series has taken us on a journey from understanding individual security models to identifying complex cross-system SoD challenges, and finally, to exploring how innovative solutions like AccessHub provide the critical capabilities for effective governance. By integrating Salesforce with SAP GRC through normalized data, organizations can achieve true end-to-end access visibility and proactive risk mitigation.
Don’t let cross-system complexities compromise your security posture. Take the next step:
- Read Part 2: Bridging the Divide: Understanding Cross-System SoD Challenges Between Salesforce and S/4HANA
Ready to implement a robust cross-system SoD solution for your enterprise? Contact us today to learn how AccessHub can empower your access governance strategy.

