SOA People - Blogs and News about SAP technologies

Managing SAP Authorization Requests with AI: A First Look at the AI Role & Authorization Assistant

Written by SOA People | September 17, 2026

Anyone who works in a corporate SAP environment has asked this question at least once: "How do I get access to that transaction code or Fiori app?" It sounds simple, but behind it hide dozens of emails, multiple approval steps, and a wait that can stretch on for days. That is exactly the problem we set out to solve. We designed a solution that digitizes SAP authorization requests end to end and backs them with artificial intelligence: the AI Role & Authorization Assistant.

In this article we'll look at where things stand today, the challenges teams face, the modules that make up the solution, and — most importantly — the role artificial intelligence plays throughout the process.

How Is SAP Authorization Managed Today?

In SAP systems, before a user can perform a given task, they need a role that grants access to the relevant transaction code or Fiori application.

In most organizations this process is still largely manual. A typical request goes through these steps: First, the user tries to figure out which transaction code they need — and what that transaction code actually does. Then they email their manager or open a service-desk ticket. The manager reviews the request and, if appropriate, forwards it to the Security/Basis team. The Basis team decides which role to assign, makes the assignment, and notifies the user.

Throughout this process there is no automated control in play. Whether a user has been granted conflicting authorizations — that is, whether the principle of Segregation of Duties (SoD) has been violated — can only be noticed during periodic audits.

The Challenges of the Current Process

Lack of visibility. The user doesn't know which role they need, who will approve it, or what stage their request is at. Because the process is buried in email traffic, tracking it is nearly impossible.

Long wait times. Especially during period-end closings, project kick-offs, or new-hire onboarding, requests pile up and can take days or even weeks. During that time the user can't do their job — or has to work under someone else's account, which is both a security risk and a license violation.

Late detection of SoD conflicts. Under today's setup, a single user can be granted both purchase-order creation and invoice-verification authorizations at the same time. This combination carries internal-process risk, and misuse of the authorization can lead to harmful outcomes. Such conflicts are usually caught only in periodic reporting — by which point the risk is already entrenched.

No standardization. There's no consistent guide for which transaction code maps to which role, which parameters are required, or how to write a business justification. This creates operational load for the Basis team and leads to different users receiving different roles for the very same request.

Insufficient audit trail. There is no central, automated record showing who requested which authorization, when, with what justification, and who approved it. When audit time comes, this information has to be pieced together from email archives.

What Is the AI Role & Authorization Assistant?

The AI Role & Authorization Assistant is an application — built in the SAP Fiori design language — that brings all of these problems onto a single platform. Its core goal is to manage the entire process, from the moment a user submits an access request to the moment a manager makes a decision, with real-time SoD checks and AI support.

What sets the solution apart is that it turns the SoD check from a reactive audit tool into a proactive, preventive mechanism: conflicts that until now were caught during audits are now shown to the user and the manager right at the moment of request — before it ever reaches approval.

The application consists of four main modules.

Module 1 — New Request

Lets users start a request by entering a transaction code or Fiori application ID. This module answers the "which role should I ask for?" question before the request is even created, and removes the burden of incomplete or incorrect requests reaching the Basis team.

Module 2 — Smart Assistant (Chatbot)

This is the most innovative component of the application. The AI-powered assistant guides the user step by step to complete the request form. Once the parameters are in place, the system automatically runs the SoD check, and if there's an authorization conflict, the warning mechanism kicks in.

Another smart feature of the assistant is the Related Application Suggestion: applications that share the same authorization object are recommended, so a user can request access for multiple applications in a single request — preventing situations where related or similar applications are forgotten in the request.

Module 3 — My Requests

Presents the user's past requests, their details, and their statuses in a table, giving full visibility and transparency into the process.

Module 4 — Manager Inbox

The module where managers review and decide on requests coming from their teams, all from one central place. Once approval is given, the role assignment is carried out by triggering the relevant process.

Which Problems Does the Application Solve?

Proactive SoD control. The most critical change is that conflicts become visible at the moment of request rather than during an audit. This fundamentally lowers both compliance costs and security risk.

A faster process. Thanks to the assistant-driven flow, the Basis team no longer needs to send requests back for missing information or chase users with follow-up messages — which aims to significantly shorten the authorization timeline (final approval still depends on the manager's availability).

A central audit trail. Who requested what and when, who approved or rejected it, and the reasoning behind it are all recorded automatically — creating a ready-made foundation for internal and external audits.

Democratized knowledge. The answers to questions like "what is this transaction code or application, and which role and parameters does it require?" no longer require asking the Basis team; all of this information is instantly available within the application.

The Role of Artificial Intelligence in This Process

In this solution, AI isn't an accessory — it's at the center of the experience. Its contribution can be seen across four layers:

1. A conversational, guided experience. Instead of wrestling with complex forms, the user completes their request through a natural dialogue. The assistant knows which question to ask and when, based on context — requesting different organizational parameters depending on the module and filling in what's missing. The technical complexity of the authorization world turns into a simple conversation for the user.

2. Context-aware content suggestions. The "Related Applications" feature automatically recommends applications that are used together within the same business process. This keeps users from opening request after request for the same process, and treats authorization as a coherent whole at the business-process level.

3. A real-time risk engine. The SoD engine instantly compares the user's existing authorization profile with the requested authorization and resolves the conflict analysis within seconds. As a result, risk surfaces at the moment of request — before it ever materializes.

4. An architecture open to learning. The solution's roadmap includes strengthening the risk engine with machine learning, so it learns from past request data to refine its risk scoring. The goal is to flag unusual authorization combinations more precisely by comparing users in similar positions — in other words, an assistant that can also see the blind spots rules don't cover.

One important point: the aim is not to replace people. AI provides the speed, the context, and the insight; the decision and the responsibility still rest with the manager.

Conclusion

SAP authorization management remains one of the most critical — yet least digitized — areas of enterprise processes. The AI Role & Authorization Assistant was designed to bring user experience, process speed, security controls, and compliance management together on a single platform — with artificial intelligence at the heart of all of them.

In this article we've shared the broad strokes of the solution; the truly exciting part is seeing it in action. If you'd like to explore how the AI Role & Authorization Assistant could be deployed for your own SAP landscape, reach out to us — we'd love to discuss your specific setup and where it could make the biggest difference.