Agent 10 · Domain

2026

Security & Controls Agent

Maintains roles, authorizations, segregation of duties, privacy, security controls and compliance traceability.

Overview

The Security & Controls Agent brings access and control consequences into design decisions early.

Lifecycle: Prepare through Run
Default autonomy: Assess and recommend
Human owner: CISO or Internal Controls Owner
Typical consulting roles: SAP security architect, GRC consultant, IAM consultant, controls lead, privacy consultant

The implementation challenge

Roles and controls are frequently designed after process choices have hardened. Conflicts, excessive access and missing control evidence then appear during testing or audit preparation.

Mission and boundaries

The agent derives security and control impacts, assesses role proposals, detects conflicts and maintains traceability from risks to controls and tests.

It does not approve sensitive access, accept control deficiencies or grant production authorization.

Role across SAP Activate

  • Prepare: define security architecture, control framework and ownership.
  • Explore: assess process roles, sensitive activities and control requirements.
  • Realize: support role design, testing and remediation.
  • Deploy: evaluate access and control readiness.
  • Run: monitor conflicts, privileged access and control effectiveness.

Key use cases

  • derive authorization needs from process steps.
  • identify segregation-of-duties conflicts in proposed roles.
  • map a process change to affected controls.
  • prepare access-test and audit evidence.
  • monitor time-bound emergency access.

Required skills

SAP authorization concepts, GRC, IAM, segregation of duties, business controls, privacy, security architecture, audit evidence and process-specific risk.

How it works

Inputs include process models, organizational structures, roles, users, control catalogs, access logs and test results. Outputs include proposed role impacts, conflict findings, mitigation options, control mappings and evidence.

Human–agent operating model

The agent performs continuous analysis and evidence maintenance. Security architects design policy. Business and control owners decide access, mitigation and risk acceptance.

Governance and risks

This agent handles highly sensitive information and could itself become a privileged target. Least privilege, independent approval, data minimization and immutable logging are essential.

Success and maturity

Measures include excessive-access reduction, conflict remediation time, control coverage, access-test defects and audit findings.

Example

A new shared-service role combines vendor maintenance and payment approval. The agent identifies the conflict, proposes role separation and routes mitigation options to the Controls Owner.

Process / Fit-to-Standard Agent, Solution Design Agent, Data Migration & Quality Agent, Integration Agent, Testing & Quality Agent, Segregation-of-Duties Reviewer and Evidence Validator.