MTC Skopos is a specialized access risk analysis tool for SAP and multi-ERP landscapes, built by SAP security consultants. It runs as a portable desktop application: no server, no agent, no cloud upload, no telemetry. Authorization data stays on the machine running the analysis.
The tool works fully offline from standard SAP table exports (USR02, AGR_USERS, AGR_1251, UST12), which the Basis team can produce in 5 to 10 minutes, or via RFC extraction in 1 to 5 minutes. A full authorization-level analysis of a 10,000-user system completes in under 2 minutes on a standard laptop; a single-user check returns in under a second.
The included template ruleset covers 350+ SoD risks, 700+ critical access checks, and 100+ authorization quality checks, editable down to authorization-object level and convertible to SAP GRC format. Beyond SAP ECC and S/4HANA, it analyzes Odoo, Microsoft Dynamics NAV, Sage, PeopleSoft, Kyriba, and any other system through a generic user-privilege format.
Optional modules: Advanced Remediation (concrete fix steps ranked by least disruption), Did-Do Analysis (which conflicts were actually exercised), Simulation, Cross-System rules, and IAM Business Roles. AI assistants such as Claude Desktop and Copilot connect through Model Context Protocol without data leaving the machine.
Pricing is public: €5,736/year base license, €555 per additional seat, no per-user or per-system fees. One license covers unlimited systems and analyzed users. 14-day free trial on your own data.