Skip to content
E
ERPResearch
Xiting Authorizations Management Suite (XAMS) logo

Xiting Authorizations Management Suite (XAMS)

by Xiting AG · Access Controls & SoD

SAP-certified suite for automating SAP role design, access risk and SoD projects.

Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.

Works with
SAP
Deployment
On-premise
Pricing
Quote-based
Founded
2008
Headquarters
Switzerland

Overview

XAMS (Xiting Authorizations Management Suite) is an on-premise SAP add-on for automating SAP authorization projects, built by Swiss SAP-security specialist Xiting AG. It follows what Xiting calls a Get Clean, Stay Clean approach: first restructuring bloated or over-permissive SAP role concepts down to least-privilege, then keeping them clean over time with rule-based, automated role maintenance rather than manual rework.

The suite is organized into several components covering role design (trace-based, using actual usage data), code analysis, mass role processing, production-safe role testing, time-boxed emergency access with full audit trails, an analytical reporting layer with 100+ reports, and automated generation of a documented SAP security concept. It also includes direct SU24 integration to stay aligned with SAP standard authorization maintenance, and a connector for feeding SAP security events into an external SIEM.

Xiting positions XAMS heavily around S/4HANA migration projects, where trace-based role redesign and Simplification List-aware tooling are used to cut authorization remediation effort. The company reports 700+ customers worldwide and holds SAP-certified integration status for SAP S/4HANA and SAP S/4HANA Cloud (since 2023).

Screenshots & demo

Demo video from the vendor's YouTube channel.

Features & capabilities

Role Design and Optimization

Trace-based role design and mass role processing.

  • Trace-based role design applying least-privilege principles
  • S/4HANA migration support via Simplification List awareness
  • Direct SU24 integration for SAP standard authorization maintenance
  • Automated, rule-based role building to reduce manual errors
  • Mass role processing and replication across role landscapes
  • ABAP code analysis to inform authorization checks

Segregation of Duties and Risk

Risk detection built on integrated rule sets.

  • Integrated risk and license rule sets for compliance checks
  • Systematic reduction of SoD risks and critical authorizations
  • 100+ analytical reports on roles and authorizations
  • Authorization landscape profiling and overlap detection

Testing and Production Safety

Validates role changes before they reach live users.

  • Role testing in a non-production environment before rollout
  • Automated checks to catch authorization errors pre-deployment
  • Fiori app and tile management as part of role builds

Emergency Access and Monitoring

Time-boxed privileged access with full traceability.

  • Time-based emergency (firefighter) access provisioning
  • Complete audit trail of emergency access sessions
  • SIEM connector for real-time SAP security event monitoring

Security Architecture and Compliance

Documents and enforces the authorization concept.

  • Automated generation of a documented SAP security concept
  • DSAG-aligned compliance standards
  • Internal control system with automated security checks
  • Audit-proof logging across authorization changes

Common use cases

  • Cleaning up a bloated or over-permissive SAP authorization concept and keeping it maintained long-term
  • Accelerating SAP S/4HANA migration by using trace-based role redesign against the Simplification List
  • Building least-privilege SAP roles from actual usage traces rather than copying existing roles
  • Managing SoD risk and critical-authorization exposure across a large SAP role landscape
  • Running audit-proof, time-boxed emergency (firefighter) access for support and admin teams
  • Testing role changes safely before pushing them to a production SAP system
  • Feeding SAP authorization and security events into an external SIEM for monitoring

Strengths & considerations

Strengths

  • SAP-certified integration with SAP S/4HANA and SAP S/4HANA Cloud since 2023
  • Trace-based, usage-driven role design rather than purely template or copy-based role building
  • Direct SU24 integration keeps role structures aligned with SAP standard authorization maintenance
  • On-premise deployment keeps authorization data inside the customer SAP system
  • 700+ customers and a dedicated SAP-security consulting practice behind the product

ERP integrations

SAP add-on (installed within the SAP system)Bi-directionalSAP-certified for SAP S/4HANA and SAP S/4HANA Cloud

Direct SU24 integration; supports all SAP releases

Pricing

Model
Quote-based

Most ERP add-on vendors quote based on company size, modules and integration scope. Get an independent shortlist with pricing guidance below.

Technical & security

Hosting
Installed as an add-on within the customer SAP system
Compliance
ISO 27001

About the vendor

Founded
2008
Headquarters
Switzerland
Employees
~140

Alternatives to Xiting Authorizations Management Suite (XAMS) in Access Controls & SoD

Xiting Authorizations Management Suite (XAMS) — frequently asked questions

Is XAMS SAP-certified?

Yes. XAMS holds SAP-certified integration status for SAP S/4HANA and SAP S/4HANA Cloud, effective since 2023, and Xiting is an SAP Silver Partner.

Does XAMS help with SAP S/4HANA migration?

Yes. Its Role Designer component uses trace-based analysis and Simplification List awareness to redesign roles for S/4HANA, which Xiting cites as cutting migration effort significantly compared to manual role rebuilds.

What does XAMS Get Clean, Stay Clean mean?

It describes the two-phase approach behind XAMS: first restructuring an existing, often bloated SAP authorization concept down to least-privilege roles, then using automated, rule-based tooling to keep that structure clean as the system evolves.

Does XAMS include emergency access management?

Yes, through its Xiting Times component, which provisions time-boxed emergency (firefighter) access with a complete audit trail of what was accessed during the session.

Where does XAMS run?

XAMS is deployed on-premise as an add-on installed within the customer own SAP system, rather than as an external cloud service.

Evaluating Access Controls & SoD?

Tell us your ERP and requirements and we'll send an independent shortlist — including Xiting Authorizations Management Suite (XAMS) and the best-fit alternatives — with honest pros and cons.

By submitting, you agree that ERP Research may share your details with matched ERP implementation partners, who may contact you about your enquiry. Privacy policy

Join 2,000+ companies using ERP Research to find their ideal ERP