Find partners
SAP Security & GRC

SAP Security & GRC

Hosted by Soterion

Episodes

38

Latest episode

Jul 2026

Language

EN-ZA

About the show

Soterion’s SAP Security & GRC podcast with host Dudley Cartwright, helping you on your journey to effective access risk management in SAP. Soterion is an international leading provider of GRC and FUE Licensing solutions for organisations running SAP. Our user-friendly, plug-and-play software integrates immediately into the SAP environment — S/4HANA ready, award-winning, and designed to translate complex GRC processes into business-friendly language. Soterion believes that effective GRC is measured by how well business users can manage access risk. Our solutions empower organisations to enhance risk awareness, drive better decision making, and build accountability across every level of the business — because access risk is business risk.

Listen to episodes

38 recent
July 9, 2026Episode 1114 min

How to Set up and Analyse STUSOBTRACE

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In this episode, Ross Robertson covers the SAP Authorisation Trace at the application level – STUSOBTRACE – which reveals exactly what authority checks a given SAP application (a transaction, Fiori OData service, RFC function module, or background job) performs at runtime. It’s the final piece in our authorisation tracing mini-series, following STAUTHTRACE (E09) and STUSERTRACE (E10). 🔑 Key Takeaways: What STUSOBTRACE is and how the application-level view differs from STAUTHTRACE and STUSERTRACE How to activate it via the auth/authorization_trace parameter in both the dynamic (RZ11) and static (RZ10) profiles Parameter values N / Y / F – and why Y usually works at the application level while the per-user trace leans on F How unique-once recording keeps it viable as a long-term trace Why the “changed by” user is only the first to trigger a check – and the analysis trap to avoid Analysing by application or by authorisation object (e.g. every transaction that calls an object for Activity 01) Real use cases: building SU24 authorisation defaults or identifying S/4HANA high-tier license usage. 👥 Featuring: Ross Robertson – Senior SAP Authorisations Consultant, Soterion 🎧 Take me to the Podcast: https://soterion.com/podcast/

July 3, 2026Episode 1018 min

How to Set Up and Analyse STUSERTRACE

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In this episode, Ross Robertson walks through the SAP User Authorisation Trace (STUSERTRACE) – a long-term authorisation trace that records unique authority checks per user in the background, making it invaluable for everything from day-to-day authorisation management to full role redesigns. Where STAUTHTRACE (covered in E09) captures a short window of activity, STUSERTRACE keeps a long-term history you can analyse months – even a year – later. 🔑 Key Takeaways: What STUSERTRACE is and how it differs from the short-term STAUTHTRACE How it stays lightweight by logging each unique authority check only once per user How to activate it via the auth/authorization_trace profile parameter – and why you set it in both the dynamic (RZ11 / RZ10) and static (RZ10) profiles Parameter values explained: N (off), Y (active, no filter), F (active with a filter) – and why Soterion recommends F with exclusions Which users and authorisation objects to exclude (e.g. high-volume objects with constantly changing fields like order numbers) to protect system performance How to evaluate results by user, application type, authorisation object, check result, CDS entity, and date range Real consulting use cases: building SU24 authorisation defaults from real usage and excluding developer / firefighter activity from business-as-usual role design Featuring: Ross Robertson – Senior SAP Authorisations Consultant, Soterion

July 1, 2026Episode 914 min

How to Set up and Analyse STAUTHTRACE

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In this episode, Ross Robertson walks through the SAP short-term user authority check trace (STAUTHTRACE) – a real-time authorisation trace that captures both successful and failed authority checks as users execute transactions, Fiori apps, and RFC calls. Think of it as a far more powerful evolution of the classic SU53 report. 🔑 Key Takeaways: What STAUTHTRACE is and how it differs from the classic SU53 report How to activate the trace system-wide or on a specific application server Why STAUTHTRACE runs on a rolling memory buffer with minimal system impact – so you can leave it active long-term How to filter results by user, date/time, application type, application name, authorisation object, and check result A live troubleshooting walkthrough: diagnosing a failed SU01 user-change authorisation (S_USER_GRP) Reading both passed and failed checks – including table access checks in SE16 (e.g. EKKO) and CDS view entity checks in S/4HANA Inspecting the user buffer via SU56 👥 Featuring: Ross Robertson – Senior SAP Authorisations Consultant, Soterion

June 23, 2026Episode 814 min

How to Convert an Authorisation Field into an Organisational Level Field

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In this episode, Ross Robertson , SAP Senior Authorisations Consultant at Soterion, walks through how to convert an authorisation field into an organisational level field within SAP role design – and explains exactly why this matters for centralised, scalable authorisation management. 🔑 Key Takeaways: The difference between authorisation fields and organisational level fields in SAP Why org level fields enable centralised maintenance across multiple authorisation objects within a role How org levels behave independently in parent and derived role designs – protecting child role values from being overwritten How to convert an authorisation field to an organisational level using SAP’s built-in functionality Practical business case using movement type (BWART) in a goods movement role If you work with SAP role design, authorisations, or GRC and want to streamline how you manage authorisation values across derived roles, this episode is for you. 👥 Featuring: Ross Robertson – Senior SAP Authorisations Consultant, Soterion

April 28, 2026Episode 726 min

Technical Series: Using LSMW in SAP Authorisation Management

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In this episode, Ross Robertson and Wehmeyer Ferreira , SAP Senior Authorisations and Security Consultants at Soterion, walk through how to use the Legacy System Migration Workbench (LSMW) to perform mass maintenance of data subjects in SAP – specifically focused on bulk role deletions within the authorisations space. Key Takeaways: What LSMW is and how it fits into SAP authorisations administration How to set up and configure an LSMW recording for batch processing How to perform mass role deletions across hundreds of roles using a structured input file How to review batch results and handle errors after execution Why LSMW is a time-saving alternative to manual PFCG processing If you are managing SAP role administration, authorisations, or security and looking to reduce manual workload through automation, this episode is for you. Featuring: Ross Robertson – Senior SAP Authorisations Consultant, Soterion Wehmeyer Ferreira – SAP Senior Authorisations and Security Consultant, Soterion Connect with Soterion: More Podcast Episodes: https://soterion.com/podcast/ Website: https://soterion.com/ LinkedIn: https://www.linkedin.com/company/soterion/

March 31, 2026Episode 613 min

Technical Series: How to Create and Maintain Fiori Spaces & Pages

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In this session Ross Robertson focuses on the creation, maintenance, and administration of Fiori Spaces and Pages , which determine how SAP Fiori applications are organised and presented to end users. 🔑 Key Takeaways: • Fiori Spaces are the top level of the Launchpad structure and are used to organise business functions for end users. • Pages and Sections help structure apps within a Space, making it easier for users to navigate and access the tools they need. • Fiori Tiles are placed inside Sections and represent the individual applications users interact with. • Keeping configurations lean and well-structured improves SAP Fiori Launchpad performance and reduces load times. • Both Fiori Catalogues and Spaces must be assigned to roles to ensure users can access the correct apps in the Launchpad. Through this walkthrough, viewers gain a practical understanding of how to configure Fiori Spaces and Pages effectively, ensuring users can quickly access the applications they need while avoiding performance issues caused by over-allocation of tiles and target mappings. Don’t miss out on insights from: Ross Robertson – Senior SAP Authorisations Consultant - Soterion For more episodes visit: https://soterion_sapsecuritygrc.buzzsprout.com/

February 10, 2026Episode 510 min

Technical Series: How to Create and Maintain SAP Fiori Catalogs

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In this short, practical session, Ross Robertson will walk through how to create a custom SAP Fiori catalog to give users access to specific apps, tiles, and target mappings — using SAP-recommended best practices. Key takeaways: · An overview of SAP Fiori catalogs and their role in authorisation and UX · How to create custom catalogs using Fiori Content Manager · Why SAP technical catalogs should be used as references · How to identify the correct tiles and target mappings via the SAP Fiori App Library · A simple but critical service check to prevent broken navigation and OData issues Don’t miss out on insights from industry expert: · Ross Robertson – Senior SAP Consultant - Soterion For more episodes visit: https://soterion_sapsecuritygrc.buzzsprout.com/

December 2, 2025Episode 424 min

Technical Series: How to Make use of SAP SU24 Variants

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In this session, we walk through a practical, real-world demonstration of how SU24 authorization defaults and SU24 variants can significantly reduce manual maintenance when building SAP roles. Using the widely-used MIGO transaction as an example, we show you how different business processes (such as Goods Receipts and Goods Issues ) often require different movement types — and how SU24 variants make it possible to standardise and automate these differences cleanly. What you’ll learn from this episode: 🔹 How SU24 authorisation defaults work and why they’re essential for effective SAP design, with a low support burden. 🔹 The problem with repeated manual maintenance when using MIGO across multiple roles 🔹 How to create and transport SU24 variants for different business scenarios 🔹 How variants ensure consistency across role builds while reducing effort and risk 🔹 A step-by-step walkthrough of building two roles using variants for GR and GI Don’t miss out on insights from: Emile Steyn - Business Unit Manager – Soterion Benelux Ross Robertson – Senior SAP Authorisations Consultant - Soterion

December 2, 2025Episode 38 min

Technical Series: How to Build SAP Single Roles

Listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In our latest technical series episode, we unpack one of the most important building blocks in SAP authorisations: single roles. Our experts explore the different ways organisations design single roles to balance provisioning efficiency, SoD risk reduction, and long-term maintainability. Key Takeaways: 🔹 The difference between task/functional roles and value/enabler roles 🔹 Why some companies prefer job-role-based design for easier provisioning 🔹 The hidden pitfalls of job roles — including SOD risk and over-allocation 🔹 How parent & derived roles simplify maintenance across large landscapes 🔹 The role methodologies that influence risk, licensing and long-term scalability Don’t miss out on insights from: Emile Stey - Business Unit Manager – Soterion Benelux Cameron Mattison – Senior SAP Authorisations Consultant - Soterion Ross Robertson – Senior SAP Authorisations Consultant - Soterion For more episodes, visit: https://soterion_sapsecuritygrc.buzzsprout.com/

November 11, 2025Episode 28 min

Technical Series: Authorisation Default Values

Watch or listen to the SAP Security & GRC podcast – helping you on your journey to effective access risk management in SAP. In our latest technical podcast episode , we dive deep into a crucial piece of the SAP authorisation puzzle — authorisation default values . You’ll discover: How authorisation defaults determine which checks are performed during transaction execution The difference between SAP standard defaults (SU22) and customer-specific defaults (SU24) How to handle complex transactions like MIGO with multiple business functions Why fine-tuning these defaults helps avoid over-assignment and license exposure Don’t miss out on insights from industry experts: Emile Steyn, Business Unit Manager – Soterion Benelux Ross Robertson – Senior Consultant - Soterion For more episodes visit: https://soterion_sapsecuritygrc.buzzsprout.com/

Is this your show?

Claim this listing to keep it up to date, reach guests who want to pitch you, and manage bookings with Guestify.

Claim this listing

More Technology podcasts