
As a SAP Security & Authorization consultant, I run analyses on client environments without waiting for a full enterprise GRC deployment. Uploading a role catalogue and user assignments as flat files gives me a working SoD, SAT and FUE analysis in one afternoon.
The what-if capability changed how I present recommendations. Instead of "remove this transaction", I show clients the FUE impact instantly - data-driven trade-offs beat opinions every time.
What I use most:
-Bulk role import via XML or file upload
-SoD ruleset with sensible defaults for standard SAP areas
-Risk definitions in business terms - process owners read reports without me translating
The UI is genuinely intuitive, which is rare in the GRC category. Review collected by and hosted on G2.com.
The API documentation could be more detailed - I had to reach out to support when integrating smartGRC with a client-side automation pipeline. Mobile experience is also limited (understandable for a GRC tool, but occasionally I need a quick check from my phone during a client meeting). Nothing that blocks day-to-day work, but worth flagging for consultants who juggle multiple client environments in parallel. Review collected by and hosted on G2.com.