Skip to content
E
ERPResearch
Pathlock logo

Pathlock

by Pathlock · SOX & Internal Controls

Identity governance and access-risk automation for SOX controls across SAP, Oracle, Workday.

Updated August 2026 · By the ERP Research Editorial Team · Independent and vendor-neutral.

Works with
SAPSAP S/4HANAOracleWorkdayMicrosoft Dynamics 365PeopleSoft
Deployment
Cloud
Company size
Mid-market, Enterprise
Pricing
Quote-based
Headquarters
1675 Larimer St, Suite 700, Denver, CO 80202, United States

Overview

Pathlock is a compliance-centric identity governance and application-GRC platform that secures and governs human and non-human identities across ERP systems and other business-critical applications. The platform brings together identity and access governance, application-level GRC (segregation of duties, emergency access, dynamic data access control), continuous controls monitoring, and ERP cybersecurity in a single suite, aimed primarily at automating SOX 302/404 compliance, SoD analysis, and IT general controls for mid-market and large enterprises.

Core modules include Application Access Governance (fine-grained SoD and sensitive-access risk analysis across SAP, Oracle, Workday, PeopleSoft and other applications), Compliant Provisioning (automated joiner/mover/leaver workflows), Access Certifications (automated user access reviews), Elevated Access Management (time-bound privileged/firefighter access with full audit trails), Role Management, Dynamic Access Control (real-time data masking and transaction blocking), Continuous Controls Monitoring (automated control testing and financial-impact analysis of 100% of transactions), and Cybersecurity Application Controls (vulnerability management, threat detection, transport/code-change control for SAP).

Pathlock reports over 1,300 customers, including Aramco, P&G, Jabil, Chevron, Toyota, Siemens, Microsoft, Electrolux and the University of California, and is delivered as a cloud SaaS platform ("Pathlock Cloud") with pre-built connectors for 150+ applications plus no-code tools for custom integrations.

Screenshots & demo

Demo video from the vendor's YouTube channel. Screenshots sourced from Pathlock.

Features & capabilities

Identity & Access Governance

Automates core identity lifecycle and access-request processes across ERP and business applications.

  • Compliant provisioning (automated joiner/mover/leaver onboarding and offboarding)
  • Self-service access request portal
  • Automated manager access certifications and user access reviews
  • Role management with automatic entitlement grouping by job title
  • Non-human identity governance for service accounts and bots
  • AI-powered role suggestions to resolve conflicts without disrupting access

Application GRC / Access Risk Analysis

Detects and remediates segregation-of-duties and sensitive-access risk across the application landscape.

  • Fine-grained Segregation of Duties (SoD) conflict detection across SAP, Oracle, Workday and PeopleSoft
  • Cross-application SoD analysis rather than single-system checks
  • Emergency / firefighter access with full workflow tracking
  • Dynamic Access Control: real-time data masking and sensitive-transaction blocking
  • Entitlement design and testing for compliant ERP roles
  • Out-of-the-box risk rulesets, customizable to organizational risk appetite
  • Peer benchmarking and risk-impact simulation before access changes

Continuous Controls Monitoring & Audit

Automates control testing, transaction analysis, and audit evidence collection.

  • Continuous Controls Monitoring (CCM) with real-time compliance-rule alerts
  • Enriched transaction monitoring to analyze 100% of transactions for financial impact
  • Centralized Controls Management mapping controls to regulations, risks and policies
  • Risk Quantification of financial exposure to prioritize remediation
  • Change Monitoring for critical configuration and master-data changes
  • Tamper-proof audit trails of who changed what data and when
  • Out-of-the-box audit reporting for external auditors

ERP Cybersecurity

Secures the underlying ERP application layer against vulnerabilities and unauthorized changes.

  • Vulnerability management to find and patch security gaps in core business systems
  • Real-time threat detection for active attacks on financial systems
  • Transport/code-change control to prevent malicious or flawed updates reaching production
  • Cybersecurity Application Controls delivered without touching the SAP core

Common use cases

  • Automating SOX 302/404 IT general controls (access reviews, provisioning, change tracking) for a public company's annual audit
  • Continuously identifying and remediating SoD conflicts across SAP and Oracle instead of relying on periodic manual reviews
  • Streamlining user access certifications so managers can complete SOX-required reviews on time with full audit evidence
  • Granting and logging privileged/firefighter access in SAP with automated revocation to control elevated-access SOX risk
  • Preparing for UK-SOX by automating internal controls and IT access security ahead of upcoming reporting deadlines
  • Masking or blocking sensitive SAP transactions in real time via Dynamic Access Control to reduce role explosion
  • Consolidating access-risk and controls-monitoring evidence across SAP, Oracle and Workday into a single audit-ready reporting layer

Strengths & considerations

Strengths

  • Cross-application SoD and access-risk analysis spanning SAP, Oracle, Workday, PeopleSoft and other systems from one platform, versus single-system tools like native SAP GRC
  • Fine-grained, permission-level risk analysis of actual user activity (not just theoretical access) to reduce false positives
  • Continuous Controls Monitoring analyzes 100% of transactions for financial impact rather than sampling
  • Cybersecurity Application Controls layer (vulnerability management, threat detection, transport control) bundled alongside identity governance and GRC
  • Pre-built connectors for 150+ applications plus a no-code Connector Studio for custom integrations

ERP integrations

Pre-built connector

Covers SAP ERP (ECC) and SAP Ariba; delivered without modifying the SAP core

Pre-built connector
Pre-built connector

Covers Oracle E-Business Suite and Oracle ERP Cloud

Pre-built connector
Pre-built connector
PeopleSoft
Pre-built connector

Including PeopleSoft Campus Solutions

Pricing

Model
Quote-based

Pathlock does not publish pricing on its website; the /pricing/ URL returns no content and every CTA routes to "Schedule Demo" / "Book One-to-One Demo". Quotes are provided after a sales consultation. Get an independent shortlist with pricing guidance below.

Technical & security

Hosting
SaaS (Pathlock Cloud)
Compliance
ISO 27001, SOC 1 Type II, SOC 2 Type II

About the vendor

Headquarters
1675 Larimer St, Suite 700, Denver, CO 80202, United States

Alternatives to Pathlock in SOX & Internal Controls

Pathlock — frequently asked questions

Does Pathlock automate SOX 302 and 404 compliance?

Yes. Pathlock's SOX use case page states it automates SOX 302 and 404 compliance through continuous SoD analysis, compliant provisioning, periodic access certifications, and elevated-access management, producing audit-ready evidence for external auditors.

What ERP systems does Pathlock integrate with?

Pathlock provides pre-built connectors for 150+ applications, including SAP ERP, SAP S/4HANA, SAP Ariba, Oracle E-Business Suite, Oracle ERP Cloud, Workday, Microsoft Dynamics 365 and PeopleSoft, plus no-code tools in its Connector Studio for custom integrations.

What security certifications does Pathlock hold?

According to Pathlock's privacy policy, the company maintains and undergoes regular audits for ISO 27001, SOC 1 Type 2, and SOC 2 Type 2 certifications.

Can Pathlock analyze segregation-of-duties risk across more than one application at once?

Yes. Pathlock's Access Risk Analysis product analyzes SoD and sensitive-access risk across SAP, Oracle, Workday, PeopleSoft and other applications from a single platform, rather than one system at a time as with native SAP GRC.

Does Pathlock publish its pricing?

No. Pathlock does not publish pricing on its site; prospects schedule a demo or request a quote, and pricing is provided through a sales consultation.

Evaluating SOX & Internal Controls?

Tell us your ERP and requirements and we'll send an independent shortlist — including Pathlock and the best-fit alternatives — with honest pros and cons.

By submitting, you agree that ERP Research may share your details with matched ERP implementation partners, who may contact you about your enquiry. Privacy policy

Join 2,000+ companies using ERP Research to find their ideal ERP