Role and authorization design
A coherent role architecture instead of accumulated exceptions.
- Workplace and task-based role models
- Naming conventions and governance
- Derived roles across organisational levels
- PFCG, SU24 maintenance, proposal values
SAP Security & Authorizations
I design and remediate SAP authorization models — from role architecture through segregation of duties to S/4HANA migration. Independent, remote by default, working across European and Asian time zones.
The problem
Anyone who can create a vendor and release a payment can pay themselves. Combinations like these are rarely granted on purpose — they accumulate in roles over years of incremental change.
I make them visible, rank them by actual risk, and rebuild roles so they disappear. Before an audit finds them.
| Create vendor | Create PO | Goods receipt | Post invoice | Release payment | |
|---|---|---|---|---|---|
| Z_MM_PURCH | |||||
| Z_MM_STOCK | |||||
| Z_FI_VENDOR | |||||
| Z_FI_PAYRUN |
Services
My focus is authorizations and access compliance in SAP — both the design work and the technical implementation.
A coherent role architecture instead of accumulated exceptions.
The control objectives that ITGC and SoD testing address under SOX, IDW PS 330 and comparable audit frameworks.
Authorizations that survive the platform change intact.
Processes that grant and revoke access traceably.
Redesigning roles at scale without freezing the business.
Second competency area: interfaces and data exchange.
Projects
All delivered in the German enterprise market, remotely. Client names are not published here — happy to discuss specifics directly.
Ongoing
Workplace role model and S/4HANA readiness across more than 180 company codes.
Ongoing
SAP security and GRC in a heavily regulated public sector environment with formal evidence requirements.
Completed
Full S/4HANA transformation on a Bluefield approach, including Fiori authorizations across the project lifecycle.
Tooling
Large authorization landscapes cannot be remediated by hand. Specialist tooling makes it possible to rebuild roles from actual usage, simulate the outcome before anything reaches production, and test rulesets against the live system.
Working together
Every project I take on sits between two requirements that rarely align on their own: authorizations have to hold up under audit, and the people using the system have to get their work done. A design that serves only one of the two does not last.
Getting there is seldom a matter of spot fixes. Authorization landscapes that have grown over years cannot sensibly be patched further — a cleanly cut role model that reflects organisational structure and actual usage is the more durable answer.
My background is in SAP integration; I moved into security through interface and ABAP work. That origin helps. Knowing how authority checks actually behave in code leads to more realistic designs.
Contact
A short description of what you are dealing with is enough. I usually reply within two working days.