Skip to content
E
ERPResearch
MTC Skopos logo

MTC Skopos

by Meylan Technologies and Consulting · Access Controls & SoD

Portable, no-server SAP segregation-of-duties and access risk analysis tool.

Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.

Works with
SAPOracle PeopleSoftMicrosoft Dynamics
Deployment
On-premise
Pricing
Subscription (flat-rate annual license)
Founded
2024
Headquarters
Geneva, Switzerland

Overview

MTC Skopos is a segregation-of-duties and access risk analysis tool built by Meylan Technologies and Consulting, aimed primarily at SAP customers but able to ingest table exports from other ERPs. It is positioned as a lighter-weight alternative to SAP GRC Access Control: a desktop application that loads standard SAP authorization tables (USR02, AGR_USERS, AGR_1251, UST12, among others) via RFC connection or CSV export and runs the risk analysis locally, without a server, agent, or cloud upload step.

The product performs authorization-object-level SoD and critical-access analysis rather than transaction-code-level scanning, and adds a did-do layer that cross-references detected access risk against actual transaction usage (via ST03N/STAD statistics and CDHDR/CDPOS change documents) so remediation can be prioritized by what was actually exercised rather than only by theoretical risk. It also includes a permission-simulation feature for testing role and reassignment changes before they go to production, and exports results to CSV, JSON, Parquet, Power BI and Tableau.

MTC Skopos is built by Meylan Technologies and Consulting Sarl, a Geneva-based company; the product itself was launched in 2024.

Features & capabilities

Access Risk Analysis

Core SoD and critical-access detection engine.

  • Segregation-of-duties conflict detection at the authorization-object level
  • Critical/sensitive access detection (user master maintenance, ABAP debug, RFC configuration, client copy)
  • Cross-system risk analysis spanning multiple connected ERPs
  • Organizational-scope violation detection (cross company code, plant, profit center)
  • User and role-level risk views
  • Interactive user and role explorer for navigating authorization structures

Did-Do Analysis and Prioritization

Correlates theoretical access risk with actual usage to prioritize remediation.

  • Correlation of SoD and critical-access findings with actual transaction execution
  • Usage statistics analysis via ST03N/STAD
  • Change document analysis via CDHDR/CDPOS
  • Over-privileged-user detection (granted access vs. used access)
  • Remediation plans ranked by business impact

Simulation and Remediation

Tests and plans access changes before they reach production.

  • What-if simulation of role changes, user reassignments and org restructures
  • Preview of new conflicts introduced or resolved before go-live
  • Automated role-design suggestions aimed at minimizing SoD risk
  • Step-by-step, impact-ranked remediation planning

Reporting and AI

Export and analysis layer for audit and executive reporting.

  • Audit-ready compliance and SoD documentation
  • Power BI and Tableau-ready report templates
  • QlikSense-compatible exports
  • JSON/CSV/Parquet exports for downstream or AI processing
  • Built-in AI assistant for querying analysis results
  • MCP server compatibility for AI-tool integration

Deployment and Data Handling

Runs as a local, no-infrastructure desktop tool.

  • Portable desktop application, no server or agent install
  • SAP data loaded via RFC connection or standard table CSV export
  • 100 percent local processing; authorization data does not leave the customer machine
  • Engineered in Rust for performance on large authorization datasets
  • Optional local LLM support to keep AI features fully offline

Common use cases

  • Running a full SAP SoD and critical-access assessment without deploying SAP GRC Access Control
  • Preparing audit-ready SoD documentation for SOX or internal-audit review
  • Prioritizing remediation using did-do (actual usage) analysis instead of theoretical can-do risk alone
  • Simulating a role redesign or reorganization before applying changes to production SAP
  • Consultants running one-off or recurring access-risk assessments across multiple SAP clients without standing infrastructure
  • CISOs and IT security teams needing cross-system access-risk visibility spanning SAP and adjacent ERPs
  • Auditors validating access controls without requesting production system access, using exported table data instead

Strengths & considerations

Strengths

  • No server, agent or cloud deployment; runs as a portable desktop app loading SAP table exports directly, versus SAP GRC multi-month rollout
  • Did-do analysis correlates access violations with actual transaction execution (ST03N/STAD, CDHDR/CDPOS), not only theoretical can-do risk
  • 100 percent local processing, with an optional local LLM so AI features can run without any cloud exposure
  • Flat annual licensing that does not scale with the number of users, systems or transactions analyzed

ERP integrations

RFC connection or standard table CSV exportSAP to product

Primary supported system; native table-based analysis

CSV import (generic connector)
CSV import (generic connector)

Pricing

Model
Subscription (flat-rate annual license)
Starting price
From EUR5,736/year (1 seat)
Free trial
Yes

Additional seats EUR555/year each; fully configured with all add-ons (remediation reports, did-do analysis, simulation, cross-system analysis, IAM business roles) runs to roughly EUR13,198/year. Price is flat and does not scale with SAP landscape size, user count or transaction volume. Monthly billing is available at a premium over the annual rate; enterprise pricing for 20+ seats is quote-based. 14-day free trial, no card required. Get an independent shortlist with pricing guidance below.

Technical & security

Hosting
Self-hosted desktop application (runs on customer-owned hardware)

About the vendor

Founded
2024
Headquarters
Geneva, Switzerland
Ownership
Private

Alternatives to MTC Skopos in Access Controls & SoD

MTC Skopos — frequently asked questions

Does MTC Skopos require SAP GRC Access Control or a server installation?

No. MTC Skopos is a portable desktop application that loads standard SAP authorization tables via RFC connection or CSV export and runs the analysis locally, without deploying a server or agent.

What is did-do analysis in MTC Skopos?

It is a correlation layer that cross-references detected SoD and critical-access risk against actual transaction usage data (ST03N/STAD statistics and CDHDR/CDPOS change documents), so remediation can be prioritized by what was actually exercised rather than by theoretical access alone.

Which systems does MTC Skopos support?

SAP is the primary, natively supported system via RFC connection or table export. Other ERPs, including Oracle PeopleSoft and Microsoft Dynamics, can be analyzed via CSV import using generic connectors.

How is MTC Skopos priced?

It uses a flat annual subscription starting at EUR5,736/year for one seat, plus EUR555/year per additional seat, with no per-user, per-system or per-transaction fees. A 14-day free trial is available.

Where is authorization data processed?

MTC Skopos processes data locally on customer-owned hardware; the vendor states authorization data does not leave the customer infrastructure, including when using its built-in AI assistant with a local LLM.

Evaluating Access Controls & SoD?

Tell us your ERP and requirements and we'll send an independent shortlist — including MTC Skopos and the best-fit alternatives — with honest pros and cons.

By submitting, you agree that ERP Research may share your details with matched ERP implementation partners, who may contact you about your enquiry. Privacy policy

Join 2,000+ companies using ERP Research to find their ideal ERP