Maria Schewtschik SAP Security & Authorizations

SAP Security & Authorizations

Authorizations that survive the audit.

I design and remediate SAP authorization models — from role architecture through segregation of duties to S/4HANA migration. Independent, remote by default, working across European and Asian time zones.

Remote EN · DE · RU Availability on request

Portrait of Maria Schewtschik
Maria Schewtschik Independent

The problem

Two permissions, one risk

Anyone who can create a vendor and release a payment can pay themselves. Combinations like these are rarely granted on purpose — they accumulate in roles over years of incremental change.

I make them visible, rank them by actual risk, and rebuild roles so they disappear. Before an audit finds them.

Segregation of duties Sample extract
Illustrative extract of a segregation of duties matrix: roles in rows, critical functions in columns. Marked cells indicate assigned authorizations; cells highlighted in red indicate a segregation of duties conflict.
Create vendor Create PO Goods receipt Post invoice Release payment
Z_MM_PURCH
Z_MM_STOCK
Z_FI_VENDOR
Z_FI_PAYRUN
Authorization assigned Conflict

Services

Where I help

My focus is authorizations and access compliance in SAP — both the design work and the technical implementation.

01 — Design

Role and authorization design

A coherent role architecture instead of accumulated exceptions.

  • Workplace and task-based role models
  • Naming conventions and governance
  • Derived roles across organisational levels
  • PFCG, SU24 maintenance, proposal values
02 — Compliance

Segregation of duties and risk

The control objectives that ITGC and SoD testing address under SOX, IDW PS 330 and comparable audit frameworks.

  • Ruleset design and tailoring
  • Risk analysis and remediation planning
  • Critical authorizations and emergency access
  • Audit preparation and evidence
03 — Migration

ECC to S/4HANA

Authorizations that survive the platform change intact.

  • Readiness assessment of existing roles
  • Rebuild rather than carry forward legacy
  • Fiori catalogs, groups and spaces
  • OData and backend authorizations
04 — Operations

GRC and access governance

Processes that grant and revoke access traceably.

  • SAP GRC Access Risk Analysis
  • Request and approval workflows
  • Periodic access recertification
  • Security log review
05 — Tooling

Tool-assisted remediation

Redesigning roles at scale without freezing the business.

  • Role rebuild from actual usage data
  • Simulation before productive change
  • SoD rulesets and conflict analysis
  • ABAP code analysis for authority checks
06 — Adjacent

SAP integration

Second competency area: interfaces and data exchange.

  • IDoc, RFC, BAPI, OData and REST
  • AIF monitoring and error handling
  • SOAMANAGER and web services
  • ABAP in an interface context

Projects

Selected engagements

All delivered in the German enterprise market, remotely. Client names are not published here — happy to discuss specifics directly.

Ongoing

International gaming and entertainment group

Workplace role model and S/4HANA readiness across more than 180 company codes.

Role design S/4HANA XAMS

Ongoing

German federal defence agency

SAP security and GRC in a heavily regulated public sector environment with formal evidence requirements.

GRC Compliance Public sector

Completed

German premium automotive manufacturer

Full S/4HANA transformation on a Bluefield approach, including Fiori authorizations across the project lifecycle.

Bluefield Fiori Automotive

Tooling

What I work with

Large authorization landscapes cannot be remediated by hand. Specialist tooling makes it possible to rebuild roles from actual usage, simulate the outcome before anything reaches production, and test rulesets against the live system.

SAP standard

  • PFCG
  • SU24 / SU25
  • STAUTHTRACE
  • SM19 / SM20 / RSAU
  • SAP GRC — ARA
  • Fiori Launchpad Designer

Specialist tooling

  • Xiting XAMS primary tool, expert level
  • Security Architect role rebuild and simulation
  • Role Profiler usage-based role design
  • CRAF SoD rulesets
  • Pathlock SAST confident hands-on use
  • IBS Schreiber rulesets

Method

  • Scrum PSM I
  • Requirements engineering
  • Stakeholder workshops
  • Change management
  • Go-live and hypercare
  • ABAP reading and analysis

Working together

How engagements run

Every project I take on sits between two requirements that rarely align on their own: authorizations have to hold up under audit, and the people using the system have to get their work done. A design that serves only one of the two does not last.

Getting there is seldom a matter of spot fixes. Authorization landscapes that have grown over years cannot sensibly be patched further — a cleanly cut role model that reflects organisational structure and actual usage is the more durable answer.

My background is in SAP integration; I moved into security through interface and ABAP work. That origin helps. Knowing how authority checks actually behave in code leads to more realistic designs.

  • FocusSAP security, authorizations, GRC
  • ContractingThrough ERP Integration & Authorization, LLC (Delaware, USA)
  • InvoicingEUR or USD
  • DeliveryRemote, project-based
  • LanguagesGerman (native), English, Russian
  • CertificationProfessional Scrum Master I
  • ProfileFull CV on request

Contact

Project or question?

A short description of what you are dealing with is enough. I usually reply within two working days.