SailPoint
by SailPoint · Access Controls & SoD
Enterprise identity security platform with Access Risk Management for SAP SoD analysis.
Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.
- Works with
SAP- Deployment
- Cloud
- Company size
- Mid-market, Enterprise
- Pricing
- Quote-based
- Founded
- 2005
- Headquarters
- Austin, Texas, United States
Overview
SailPoint Access Risk Management (ARM) is an add-on to SailPoint Identity Security Cloud that analyzes segregation-of-duties (SoD) and access risk within SAP ECC, S/4HANA and Fiori environments, whether on-premises, in the cloud, or under SAP RISE. It performs analysis down to the transaction code and authorization object level rather than only at the role level.
The product can simulate proposed access changes before they are applied to prevent violations, monitor for excessive, outdated or unused access, and provide emergency access workflows for SAP. KPI-driven dashboards give auditors and application owners visibility into SoD risk, and the module natively integrates with Identity Security Cloud so SAP access requests and certifications are managed alongside every other application in an organization's identity program.
SailPoint also offers general cross-application SoD policy management (independent of the SAP-specific ARM add-on) for detecting conflicts of interest and enforcing policies across connected systems, supporting SOX, GDPR, HIPAA and CCPA compliance programs.
Screenshots & demo
Demo video from the vendor's YouTube channel.
Features & capabilities
SAP Access Risk Analysis
Fine-grained SoD analysis for SAP environments.
- SoD analysis down to the transaction code and authorization object level
- Prebuilt rulebooks for common SoD conflicts
- What-if simulation of proposed access changes before they are applied
- Continuous monitoring for excessive, outdated or unused access
Emergency & Privileged Access
Controlled elevated access for SAP support scenarios.
- Emergency access workflows for SAP
- Automated approval routing
Certification & Reporting
Audit-ready visibility into SAP access risk.
- KPI-driven risk dashboards for executives, auditors and application owners
- Automated evidence collection for audits
- Automated compliance reporting
Identity Security Cloud Integration
Unifies SAP governance with the rest of the identity program.
- Native integration with SailPoint Identity Security Cloud
- SAP access requests handled inside standard IGA workflows
- Unified certification campaigns spanning SAP and non-SAP apps
Cross-Application SoD Policy Management
General-purpose SoD policy enforcement beyond SAP.
- Create SoD policies applied consistently across connected systems
- Automatic scanning for policy violations
- Conflict-of-interest and fraud detection
Common use cases
- Running fine-grained SoD analysis on SAP ECC or S/4HANA authorizations down to the transaction code
- Simulating a proposed SAP role or access change to catch SoD conflicts before it goes live
- Managing SAP emergency access with an audit trail
- Certifying SAP and non-SAP access from a single Identity Security Cloud campaign
- Producing SOX, GDPR or HIPAA audit evidence with automated dashboards and reporting
- Extending an existing SailPoint IGA deployment to also cover SAP RISE or cloud SAP environments
Strengths & considerations
Strengths
- Native add-on to SailPoint Identity Security Cloud, so SAP access risk sits inside the same identity platform used for broader IGA rather than a standalone SAP-only tool
- Analyzes SoD risk down to the SAP authorization-object level, not just the transaction-code level
- Backed by SailPoint's large existing IGA customer base and connector ecosystem
ERP integrations
SoD analysis for SAP ECC, S/4HANA and Fiori, including SAP RISE, at the transaction-code and authorization-object level
Pricing
Sold as an add-on to SailPoint Identity Security Cloud; pricing not publicly disclosed. Get an independent shortlist with pricing guidance below.
Technical & security
- Hosting
- SaaS (multi-tenant)
- Compliance
- SOX, GDPR, HIPAA, CCPA
About the vendor
- Founded
- 2005
- Headquarters
- Austin, Texas, United States
- Employees
- ~3,600
- Ownership
- Public (NYSE: SAIL); majority owned by Thoma Bravo
- Notable customers
- Currys
Alternatives to SailPoint in Access Controls & SoD
SailPoint — frequently asked questions
Which SAP environments does SailPoint Access Risk Management support?
It covers SAP ECC, S/4HANA and Fiori, whether hosted on-premises, in the cloud, or under SAP RISE.
Is Access Risk Management a standalone product?
No. It is sold as an add-on that integrates natively with SailPoint Identity Security Cloud, unifying SAP access requests and certifications with the rest of an organization's identity program.
Can it simulate access changes before they are applied?
Yes. The platform can simulate and analyze proposed access changes to catch SoD conflicts before they reach a production SAP system.
What compliance frameworks does it support?
SailPoint's SoD and access risk capabilities are positioned to support SOX, GDPR, HIPAA and CCPA compliance programs.
How is SailPoint Access Risk Management priced?
Pricing is quote-based and not publicly disclosed; it is sold as an add-on to Identity Security Cloud.
Evaluating Access Controls & SoD?
Tell us your ERP and requirements and we'll send an independent shortlist — including SailPoint and the best-fit alternatives — with honest pros and cons.